Vulnerabilities (CVE)

Filtered by CWE-22
Total 7723 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-26725 1 Nozominetworks 2 Central Management Control, Guardian 2024-11-21 4.0 MEDIUM 7.2 HIGH
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.
CVE-2021-26719 1 Gradle 3 Enterprise Test Distribution Agent, Maven, Test Distribution 2024-11-21 5.5 MEDIUM 6.5 MEDIUM
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious actor (with certain credentials) can perform a registration step such that crafted TAR archives lead to extraction of files into arbitrary filesystem locations.
CVE-2021-26629 2 Microsoft, Tobesoft 2 Windows, Xplatform 2024-11-21 6.8 MEDIUM 8.8 HIGH
A path traversal vulnerability in XPLATFORM's runtime archive function could lead to arbitrary file creation. When the .xzip archive file is decompressed, an arbitrary file can be d in the parent path by using the path traversal pattern ‘..\’.
CVE-2021-26619 2 Bigfile, Microsoft 2 Bigfileagent, Windows 2024-11-21 6.4 MEDIUM 7.1 HIGH
An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users.
CVE-2021-26601 1 Impresscms 1 Impresscms 2024-11-21 5.5 MEDIUM 8.1 HIGH
ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
CVE-2021-26575 1 Hpe 2 Apollo 70 System, Baseboard Management Controller 2024-11-21 7.2 HIGH 7.8 HIGH
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function.
CVE-2021-26574 1 Hpe 2 Apollo 70 System, Baseboard Management Controller 2024-11-21 7.2 HIGH 7.8 HIGH
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function.
CVE-2021-26504 1 Dgtl 1 Huemagic 2024-11-21 N/A 7.5 HIGH
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
CVE-2021-26294 1 Afterlogic 2 Aurora, Webmail Pro 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal to read files (such as a data/settings/settings.xml file containing admin panel credentials), as demonstrated by dav/server.php/files/personal/%2e%2e when using the caldav_public_user account (with caldav_public_user as its password).
CVE-2021-26293 1 Afterlogic 2 Aurora, Webmail Pro 2024-11-21 6.8 MEDIUM 9.8 CRITICAL
An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.
CVE-2021-26028 1 Joomla 1 Joomla\! 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files outside of the intended path.
CVE-2021-25864 1 Dgtl 1 Huemagic 2024-11-21 5.0 MEDIUM 7.5 HIGH
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
CVE-2021-25833 1 Onlyoffice 1 Document Server 2024-11-21 7.5 HIGH 9.8 CRITICAL
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vulnerability, a remote attacker can obtain remote code execution on DocumentServer.
CVE-2021-25511 1 Google 1 Android 2024-11-21 4.6 MEDIUM 6.3 MEDIUM
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitrary files via a path traversal vulnerability.
CVE-2021-25485 1 Google 1 Android 2024-11-21 5.8 MEDIUM 7.5 HIGH
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Oct-2021 Release 1 allows attackers to write file as system UID via BT remote socket.
CVE-2021-25452 2 Google, Samsung 4 Android, Exynos 2100, Exynos 980 and 1 more 2024-11-21 4.9 MEDIUM 5.5 MEDIUM
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device.
CVE-2021-25450 1 Google 1 Android 2024-11-21 3.3 LOW 4.5 MEDIUM
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket.
CVE-2021-25367 1 Samsung 1 Notes 2024-11-21 5.5 MEDIUM 3.7 LOW
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission.
CVE-2021-25361 1 Google 1 Android 2024-11-21 7.2 HIGH 7.9 HIGH
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications.
CVE-2021-25311 1 Wisc 1 Htcondor 2024-11-21 9.0 HIGH 9.9 CRITICAL
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.