← Back
CWE-22

9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,563)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Bosch
1Nexo Os
Jun 17, 2026
Jan 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is poss...Show more
The vulnerability allows a remote attacker to upload arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to obtain remote code execution (RCE) with root privileges on the device.Show less
1Bosch
1Nexo Os
Jun 17, 2026
Jan 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
1Unknown O
1Download Station
Jun 17, 2026
Jan 10, 2024
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file index.php. The manipulation of the argument f leads to p...Show more
A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file index.php. The manipulation of the argument f leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250121 was assigned to this vulnerability.Show less
1Inis Project
1Inis
Jun 17, 2026
Jan 9, 2024
N/A· v4
7.5 HIGH· v3
2.7 LOW· v2
A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/controller/default/File.php of the component GET Request Handler. The manip...Show more
A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/controller/default/File.php of the component GET Request Handler. The manipulation of the argument path leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The identifier VDB-250109 was assigned to this vulnerability.Show less
1Pyload
1Pyload
Jul 9, 2026
Jan 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
pyLoad 0.5.0 is vulnerable to Unrestricted File Upload.
1Zohocorp
7Manageengine Firewall Analyzer
Manageengine Netflow AnalyzerManageengine Network Configuration Manager+4 more
Jun 17, 2026
Jan 8, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB fil...Show more
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.Show less
1Boazsegev
1Iodine
Jul 14, 2026
Jan 4, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.
1S Cms
1S Cms
Jun 17, 2026
Jan 4, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.
1Samsung
2Android
Myfiles
Jun 17, 2026
Jan 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
1Samsung
2Android
Myfiles
Jun 17, 2026
Jan 4, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.
1Apktool
1Apktool
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be manipulated by attacker to place files a...Show more
Apktool is a tool for reverse engineering Android APK files. In versions 2.9.1 and prior, Apktool infers resource files' output path according to their resource names which can be manipulated by attacker to place files at desired location on the system Apktool runs on. Affected environments are those in which an attacker may write/overwrite any file that user has write access, and either user name is known or cwd is under user folder. Commit d348c43b24a9de350ff6e5bd610545a10c1fc712 contains a patch for this issue.Show less
1Automaticsystems
1Soc Fl9600 Firstlane Firmware
Jul 9, 2026
Jan 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Directory Traversal in Automatic Systems SOC FL9600 FirstLane V06 lego_T04E00 allows a remote attacker to obtain sensitive information via csvServer.php?file= with a .. in the dir parameter.
1Fuwushe
1Ifair
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Directory Traversal vulnerability in fuwushe.org iFair versions 23.8_ad0 and before allows an attacker to obtain sensitive information via a crafted script.
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the...Show more
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability.  Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server. Show less
1Hcltech
1Dryice Myxalytics
Jun 17, 2026
Jan 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a r...Show more
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory.  The product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. Potential exploits can completely disrupt or take over the application. Show less
1Zte
1Zxcloud Irai
Jun 17, 2026
Jan 3, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the  program  failed to adequately validate the user's input, an attacker could exploit this vulnerability  to escalate local privileges.
1Mattermost
1Mattermost
Jun 17, 2026
Dec 29, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks against the server.
1Wintercms
1Winter
Jun 17, 2026
Dec 29, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilat...Show more
Winter is a free, open-source content management system. Users with access to backend forms that include a ColorPicker FormWidget can provide a value that would then be included without further processing in the compilation of custom stylesheets via LESS. This had the potential to lead to a Local File Inclusion vulnerability. This issue has been patched in v1.2.4.Show less
1Oretnom23
1Medicine Tracker System
Jun 17, 2026
Dec 28, 2023
N/A· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../file...Show more
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249137 was assigned to this vulnerability.Show less
1Deepin
1Deepin Compressor
Jun 17, 2026
Dec 27, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target s...Show more
Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening crafted archives. Users are advised to update to version 5.12.21 which addresses the issue. There are no known workarounds for this vulnerability. Show less