Skip to main content

CWE archive

CWE-22 CVEs

Programmatic archive

9,479 CVEs tagged with CWE-221,258 Critical, 3,927 High, 3,899 Medium, 389 Low, 6 Unrated.

CVE-2016-9177

Published Nov 4, 2016

Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6023

Published Oct 6, 2016

Directory traversal vulnerability in the Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8343

Published Oct 5, 2016

Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8280

Published Oct 3, 2016

Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read arbitrary files via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6038

Published Sep 26, 2016

Directory traversal vulnerability in Eclipse Help in IBM Tivoli Lightweight Infrastructure (aka LWI), as used in AIX 5.3, 6.1, and 7.1, allows remote authenticated users to read a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5332

Published Aug 31, 2016

Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5664

Published Aug 26, 2016

Directory traversal vulnerability on Accellion Kiteworks appliances before kw2016.03.00 allows remote attackers to read files via a crafted URI.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5049

Published Aug 26, 2016

Directory traversal vulnerability in chat/openattach.aspx in ReadyDesk 9.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the SESID parameter in conjunction…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6138

Published Aug 5, 2016

Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6232

Published Aug 2, 2016

Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1610

Published Aug 1, 2016

Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass inte…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1605

Published Aug 1, 2016

Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5092

Published Jul 13, 2016

Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5098

Published Jul 5, 2016

Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5307

Published Jun 30, 2016

Directory traversal vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to read arbitrary files in the web-root dire…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 7,551-7,575 of 9,479 CVEsPage 303 of 380