References https://nvd.nist.gov/vuln/detail/CVE-2019-20085 https://www.exploit-db.com/exploits/47774 https://www.exploit-db.com/exploits/48311 http://packetstormsecurity.com/files/157196/TVT-NVMS-1000-Directory-Traversal.html https://www.tenable.com/cve/CVE-2019-20085 https://www.rapid7.com/db/vulnerabilities/tvt-nvms-1000-cve-2019-20085/ https://github.com/ping-0day/templates/blob/main/CVE-2019-20085.yaml https://www.clouddefense.ai/cve/2019/CVE-2019-20085 https://vuldb.com/vuln/147865 https://www.cve.org/CVERecord?id=CVE-2019-20085
Related VulnerabilitiesPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDORPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-44177: Kirby CMS 5.3.0-5.4.0 - Path TraversalWordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-54917: SeaweedFS <= 4.29 - Path Traversal File WritePoCCVE-2026-25895: FUXA <= 1.2.9 - Unauthenticated Path Traversal to Arbitrary File WritePoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCnodogsplash-lfi: Nodogsplash - Directory TraversalPoCCVE-2025-71324: Flowise - Path TraversalPoCCVE-2026-34908: UniFi OS - Authentication Bypass via Path Traversal (..%2f)PoCCVE-2026-53519: Nezha Dashboard < 2.0.13 - Path TraversalPoCCVE-2024-56511: DataEase < 2.10.4 - Authentication Bypass via Whitelist Path Traversal