Vulnerabilities (CVE)

Filtered by CWE-22
Total 10251 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1087 1 Apple 1 Iphone Os 2026-06-17 2.1 LOW N/A
Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path.
CVE-2015-1003 1 Ininet Solutions 1 Scada Web Server 2026-06-17 5.0 MEDIUM N/A
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
CVE-2015-10136 1 Zishanj 1 Gi-media-library 2026-06-17 N/A 7.5 HIGH
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3.0 via the 'fileid' parameter. This allows unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
CVE-2015-10134 1 Mywebsiteadvisor 1 Simple Backup 2026-06-17 N/A 7.5 HIGH
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2.7.10. via the download_backup_file function. This is due to a lack of capability checks and file type validation. This makes it possible for attackers to download sensitive files such as the wp-config.php file from the affected site.
CVE-2015-10105 1 Ad33lx 1 Ip Blacklist Cloud 2026-06-17 6.5 MEDIUM 6.3 MEDIUM
A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This affects the function valid_js_identifier of the file ip_blacklist_cloud.php of the component CSV File Import. The manipulation of the argument filename leads to path traversal. It is possible to initiate the attack remotely. Upgrading to version 3.43 is able to address this issue. The identifier of the patch is 6e6fe8c6fda7cbc252eef083105e08d759c07312. It is recommended to upgrade the affected component. The identifier VDB-227757 was assigned to this vulnerability.
CVE-2015-10043 1 Apollo Project 1 Apollo 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability, which was classified as critical, was found in abreen Apollo. This affects an unknown part. The manipulation of the argument file leads to path traversal. The patch is named 6206406630780bbd074aff34f4683fb764faba71. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218307.
CVE-2015-10030 1 Surpass Project 1 Surpass 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability has been found in SUKOHI Surpass and classified as critical. This vulnerability affects unknown code of the file src/Sukohi/Surpass/Surpass.php. The manipulation of the argument dir leads to pathname traversal. Upgrading to version 1.0.0 is able to address this issue. The patch is identified as d22337d453a2a14194cdb02bf12cdf9d9f827aa7. It is recommended to upgrade the affected component. VDB-217642 is the identifier assigned to this vulnerability.
CVE-2015-10024 1 Larasync Project 1 Larasync 2026-06-17 5.2 MEDIUM 5.5 MEDIUM
A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file repository/content/file_storage.go. The manipulation leads to path traversal. The name of the patch is 776bad422f4bd4930d09491711246bbeb1be9ba5. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217612.
CVE-2015-1000006 1 Recent-backups Project 1 Recent-backups 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download vulnerability in recent-backups v0.7 wordpress plugin
CVE-2015-1000005 1 Candidate-application-form Project 1 Candidate-application-form 2026-06-17 5.0 MEDIUM 7.5 HIGH
Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
CVE-2015-0984 1 Honeywell 8 Excel Web Xl 1000c1000 600 I\/o, Excel Web Xl 1000c1000 600 I\/o Uukl, Excel Web Xl 1000c100 104 I\/o and 5 more 2026-06-17 10.0 HIGH N/A
Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300 I/O UUKL, and XL1000C1000U 600 I/O UUKL controllers before 2.04.01 allows remote attackers to read files under the web root, and consequently obtain administrative login access, via a crafted pathname.
CVE-2015-0933 1 Sharelatex 1 Sharelatex 2026-06-17 3.5 LOW N/A
Absolute path traversal vulnerability in ShareLaTeX 0.1.3 and earlier, when the paranoid openin_any setting is omitted, allows remote authenticated users to read arbitrary files via a \include command.
CVE-2015-0911 1 Dounokouno 1 Transmitmail 2026-06-17 5.0 MEDIUM N/A
Directory traversal vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to read arbitrary files via vectors related to attachment handling.
CVE-2015-0906 1 Lhaplus 1 Lhaplus 2026-06-17 5.8 MEDIUM N/A
Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive.
CVE-2015-0878 1 Almail 1 Al-mail32 2026-06-17 5.8 MEDIUM N/A
Directory traversal vulnerability in CREAR AL-Mail32 before 1.13d allows remote attackers to write to arbitrary files via a crafted filename of an attachment.
CVE-2015-0867 1 Synck Graphica 1 Download Log Cgi 2026-06-17 5.0 MEDIUM N/A
Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename.
CVE-2015-0781 1 Novell 1 Zenworks Configuration Management 2026-06-17 7.5 HIGH 9.8 CRITICAL
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.
CVE-2015-0779 1 Novell 1 Zenworks Configuration Management 2026-06-17 10.0 HIGH N/A
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11.3.2 allows remote attackers to execute arbitrary code via a crafted directory name in the uid parameter, in conjunction with a WAR filename in the filename parameter and WAR content in the POST data, a different vulnerability than CVE-2010-5323 and CVE-2010-5324.
CVE-2015-0666 1 Cisco 1 Prime Data Center Network Manager 2026-06-17 7.8 HIGH 7.5 HIGH
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
CVE-2015-0665 1 Cisco 1 Anyconnect Secure Mobility Client 2026-06-17 6.6 MEDIUM N/A
The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173.