Power-Response before 2019-02-02 allows directory traversal (up to the application’s main directory) via a plugin.
CWE-22
CVE-2019-15520
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory.
CVE-2019-15323
The ad-inserter plugin before 2.4.20 for WordPress has path traversal.
CVE-2019-15326
The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal.
CVE-2019-15266
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.
CVE-2019-15039
An issue was discovered in JetBrains TeamCity 2018.2.4. It had a possible remote code execution issue. This was fixed in TeamCity 2019.1.