← Back
CWE-22

9,562 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,562)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Veritas
2Netbackup
Netbackup Appliance
Jun 17, 2026
Mar 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
1Jenkins
1Html Publisher
Jun 17, 2026
Mar 6, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether...Show more
Jenkins HTML Publisher Plugin 1.32 and earlier archives invalid symbolic links in report directories on agents and recreates them on the controller, allowing attackers with Item/Configure permission to determine whether a path on the Jenkins controller file system exists, without being able to access it.Show less
1Jeewms
1Jeewms
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateController component.
1Jeewms
1Jeewms
Jun 17, 2026
Mar 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
1Arubanetworks
1Arubaos
Jun 17, 2026
Mar 5, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could...Show more
There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to delete arbitrary files on the underlying operating system, which could lead to denial-of-service conditions and impact the integrity of the controller. Show less
1Idurarapp
1Idurar
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.
1Jetbrains
1Teamcity
Jun 17, 2026
Mar 4, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
1Langchain
1Langchain
Jun 17, 2026
Mar 4, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only fro...Show more
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/langchain-hub GitHub repository. The outcome can be disclosure of an API key for a large language model online service, or remote code execution. (A patch is available as of release 0.1.29 of langchain-core.)Show less
1Prestalife
1Product Designer
Jun 17, 2026
Mar 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the ajax...Show more
Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the ajaxProcessCropImage() method.Show less
-
-
Jun 17, 2026
Mar 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code via the format_logfile.pl file.
1Ibm
1Filenet Content Manager
Jun 17, 2026
Mar 1, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" seque...Show more
IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 261115.Show less
1Opft
1Session
Jun 17, 2026
Mar 1, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat...Show more
Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.Show less
1F Logic
1Datacube3 Firmware
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the confi...Show more
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password.Show less
1Apache
1Ofbiz
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
1Xenforo
1Xenforo
Jun 17, 2026
Feb 29, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZIP archive for Styles Import.
1Apache
1Ofbiz
Jun 17, 2026
Feb 29, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, that fixes the issue.
1Gnu
1Cpio
Jun 17, 2026
Feb 29, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --...Show more
Debian's cpio contains a path traversal vulnerability. This issue was introduced by reverting CVE-2015-1197 patches which had caused a regression in --no-absolute-filenames. Upstream has since provided a proper fix to --no-absolute-filenames.Show less
1Phillipsdata
1Blesta
Jun 17, 2026
Feb 28, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbitrary code.
1Webtrees
1Webtrees
Jun 17, 2026
Feb 28, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directo...Show more
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensitive files in other parts of the application's file system.Show less
1Mintplexlabs
1Anythingllm
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint i...Show more
Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization.Show less