2024

2023

2022

2021

2020

CVE-2020-5840 (v3: 7.5) 6 Jan 2020
An issue was discovered in HashBrown CMS before 1.3.2. Server/Entity/Resource/Connection.js allows an attacker to reach a parent directory via a crafted name or ID field.

2019

CVE-2019-10767 (v3: 7.5) 21 Nov 2019
An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the authentication is enabled (by default isn't enabled).
CVE-2019-10765 (v3: 9.8) 20 Nov 2019
iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory.

2018

CVE-2018-16283 (v3: 9.8) 24 Sep 2018
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
CVE-2018-16549 (v3: 5.3) 5 Sep 2018
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
CVE-2018-16133 (v3: 5.3) 29 Aug 2018
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

2017

CVE-2017-16172 (v3: 7.5) 7 Jun 2018
section2.madisonjbrooks12 is a simple web server. section2.madisonjbrooks12 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.

2016

CVE-2016-8204 (v3: 9.8) 14 Jan 2017
A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
CVE-2016-8205 (v3: 9.8) 14 Jan 2017
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be executed.
CVE-2016-8206 (v3: 7.5) 14 Jan 2017
A Directory Traversal vulnerability in servlet SoftwareImageUpload in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to write to arbitrary files, and consequently delete the files.
CVE-2016-8207 (v3: 7.5) 14 Jan 2017
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files including files with sensitive user information.

2015