Vulnerabilities (CVE)

Filtered by CWE-22
Total 6174 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-8913 1 Android 1 Play Core Library 2022-10-07 6.8 MEDIUM 8.8 HIGH
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
CVE-2020-9364 1 Creative-solutions 1 Creative Contact Form 2022-10-06 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could exploit this vulnerability with the "Send me a copy" option to receive any files of the filesystem via email.
CVE-2022-3389 1 Ikus-soft 1 Rdiffweb 2022-10-06 N/A 7.5 HIGH
Path Traversal in GitHub repository ikus060/rdiffweb prior to 2.4.10.
CVE-2020-10977 1 Gitlab 1 Gitlab 2022-10-06 2.1 LOW 5.5 MEDIUM
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
CVE-2020-10457 1 Chadhaajay 1 Phpkb 2022-10-06 4.0 MEDIUM 2.7 LOW
Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).
CVE-2020-10458 1 Chadhaajay 1 Phpkb 2022-10-06 5.5 MEDIUM 6.5 MEDIUM
Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (../) via the GET parameter crdir, when the GET parameter action is set to df, causing a Denial of Service.
CVE-2020-10459 1 Chadhaajay 1 Phpkb 2022-10-06 4.0 MEDIUM 2.7 LOW
Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST parameter inpCurrFolder.
CVE-2020-12112 1 Bigbluebutton 1 Bigbluebutton 2022-10-05 5.0 MEDIUM 7.5 HIGH
BigBlueButton before 2.2.5 allows remote attackers to obtain sensitive files via Local File Inclusion.
CVE-2020-20944 1 Qibosoft 1 Qibosoft 2022-10-05 6.4 MEDIUM 9.1 CRITICAL
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
CVE-2020-18127 1 Indexhibit 1 Indexhibit 2022-10-05 4.0 MEDIUM 6.5 MEDIUM
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
CVE-2020-11738 1 Snapcreek 1 Duplicator 2022-10-05 5.0 MEDIUM 7.5 HIGH
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
CVE-2020-20907 2 Metinfo, Microsoft 2 Metinfo, Windows 2022-10-05 6.4 MEDIUM 9.1 CRITICAL
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php.
CVE-2022-34429 1 Dell 1 Hybrid Client 2022-10-05 N/A 7.1 HIGH
Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.
CVE-2020-19305 1 Metinfo 1 Metinfo 2022-10-05 7.5 HIGH 9.8 CRITICAL
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
CVE-2022-40123 1 Mojoportal 1 Mojoportal 2022-10-05 N/A 6.5 MEDIUM
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.
CVE-2022-42308 1 Veritas 1 Netbackup 2022-10-04 N/A 7.1 HIGH
An issue was discovered in Veritas NetBackup through 8.2 and related Veritas products. An attacker with local access can delete arbitrary files by leveraging a path traversal in the pbx_exchange registration code.
CVE-2022-42305 1 Veritas 1 Netbackup 2022-10-04 N/A 7.5 HIGH
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to a Path traversal attack through the DiscoveryService service.
CVE-2021-33354 1 Htmly 1 Htmly 2022-10-04 N/A 8.1 HIGH
Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter.
CVE-2022-2922 1 Dnnsoftware 1 Dotnetnuke 2022-10-04 N/A 4.9 MEDIUM
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
CVE-2021-42767 1 Neo4j 1 Awesome Procedures 2022-10-04 6.4 MEDIUM 9.1 CRITICAL
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.