CWE-22
9,562 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,562)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Solarwinds 1Access Rights Manager Jun 17, 2026 Feb 15, 2024 N/A· v4 9.6 CRITICAL· v3 N/A· v2 The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Cod...Show more |
1Solarwinds 1Access Rights Manager Jun 17, 2026 Feb 15, 2024 N/A· v4 9.6 CRITICAL· v3 N/A· v2 The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote C...Show more |
1Hgiga 4Oaklouds Organization 2.0 Oaklouds Organization 3.0Oaklouds Webbase 2.0+1 moreJun 17, 2026 Feb 15, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the f...Show more |
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm client or SDK is used to save a chart whose name within the `Chart.yaml` file includes a relative path...Show more |
A directory traversal vulnerability exists in the F5OS QKView utility that allows an authenticated attacker to read files outside the QKView directory. Note: Software versions which have reached End of Technical Suppor...Show more |
The JSON datasource plugin ( https://grafana.com/grafana/plugins/marcusolsson-json-datasource/ ) is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing JSON data from a remote endpoint...Show more |
Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Sharp 2Jh Rv11 Firmware Jh Rvb1 FirmwareJun 17, 2026 Feb 14, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Path traversal vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to obtain an arbitrary file in the affected pr...Show more |
Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platforms. Treasure Data's digdag workload automation system is susceptible to a path traversal vulnerabil...Show more |
2Devfile Redhat3Openshift Openshift Developer Tools And ServicesRegistry SupportJun 17, 2026 Feb 14, 2024 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. Thi...Show more |
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read permission to files by deploying arbitrary symbolic links to a GitHub Pages site with a special...Show more |
The attacker may exploit a path traversal vulnerability leading to information disclosure. |
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability exists in OpenRefine(version<=3.7.7) where an attacker may construct a JDBC query which may read file...Show more |
Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to th...Show more |
The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configuration...Show more |
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the function EventPluginsManager::enabledPlugins of the file components/calendar/eventpluginsmanager.cpp...Show more |
1Unify 1Openscape Voice Trace Manager Jun 17, 2026 Feb 8, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated path traversal in the user interface. |
1Mitel 1Unify Openscape Xpressions Webassistant Jun 17, 2026 Feb 8, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal. |
1Lineagrafica 1Multilingual And Multistore Sitemap Pro Jun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for PrestaShop before version 1.6.6, a guest can download personal information without restriction. |
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR. |