CWE-22
9,521 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,521)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Howfor 1Qihang Media Web Digital Signage Jun 17, 2026 Dec 10, 2025 8.8 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers to delete files without authentication. Attackers can exploit the 'data'...Show more |
1Eibiz 1I Media Server Digital Signage Jun 17, 2026 Dec 10, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile...Show more |
1Spinetix 1Fusion Digital Signage Jun 17, 2026 Dec 10, 2025 8.8 HIGH· v4 8.1 HIGH· v3 N/A· v2 SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attacker...Show more |
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the file_get_contents() function. |
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-handler.php and the deleteDirectory function. |
1Jenkins 1Redpen Pipeline Reporter For Jira Jun 17, 2026 Dec 10, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/...Show more |
1Uniteddevelopers 1Document Reader\ Jun 17, 2026 Dec 10, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory traversal. |
1A1apps 1Office App Edit Word, Pdf File Jun 17, 2026 Dec 10, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal. |
DataGear v5.5.0 is vulnerable to Arbitrary File Deletion. |
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting service in which an unauthenticated attacker can invoke a method vulnerable to path traversal to read a...Show more |
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. |
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated atta...Show more |
The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient path validation in the `simple_download_counter_parse_path()` func...Show more |
PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint acce...Show more |
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. A high privileged attack...Show more |
NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to directory traversal through the App.add_media_files() function, which allows a remote attacker to read arbitrary files on the server fil...Show more |
SiYuan is self-hosted, open source personal knowledge management software. Versions 0.0.0-20251202123337-6ef83b42c7ce and below contain function importZipMd which is vulnerable to ZipSlips, allowing an authenticated user...Show more |
MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows attackers to read sensitive system files through the 'file' GET parameter. Attackers can exploit the about page by supplying file paths to...Show more |
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GE...Show more |
1Hp 2Omen Gaming Hub System Event UtilityJun 17, 2026 Dec 9, 2025 4.8 MEDIUM· v4 8.8 HIGH· v3 N/A· v2 HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. This potential vulnerability was remediated with HP System Event Utility version 3.2....Show more |