← Back
CWE-22

9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,563)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vmware
1Aria Operations For Networks
Jun 17, 2026
Aug 29, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resul...Show more
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with administrative access to VMware Aria Operations for Networks can write files to arbitrary locations resulting in remote code execution.Show less
1Pf4j Project
1Pf4j
Jun 17, 2026
Aug 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip method in the extract function.
1Pf4j Project
1Pf4j
Jun 17, 2026
Aug 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter.
1Pf4j Project
1Pf4j
Jun 17, 2026
Aug 28, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.
1Busybox
1Busybox
Jul 9, 2026
Aug 28, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
2Agendaless
Fedoraproject
2Fedora
Pyramid
Jun 17, 2026
Aug 25, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a...Show more
Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a `index.html` file that is located exactly one directory above the location of the static view's file system path. No further path traversal exists, and the only file that could be disclosed accidentally is `index.html`. Pyramid version 2.0.2 rejects any path that contains a null-byte out of caution. While valid in directory/file names, we would strongly consider it a mistake to use null-bytes in naming files/directories. Secondly, Python 3.11, and 3.12 has fixed the underlying issue in `os.path.normpath` to no longer truncate on the first `0x00` found, returning the behavior to pre-3.11 Python, un an as of yet unreleased version. Fixes will be available in:Python 3.12.0rc2 and 3.11.5. Some workarounds are available. Use a version of Python 3 that is not affected, downgrade to Python 3.10 series temporarily, or wait until Python 3.11.5 is released and upgrade to the latest version of Python 3.11 series.Show less
1M Files
1Classic Web
Jun 17, 2026
Aug 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
1Edetw
1U Office Force
Jun 17, 2026
Aug 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but c...Show more
e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service. Show less
1Icewarp
1Mail Server
Jun 17, 2026
Aug 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the l...Show more
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted server.Show less
1Filemage
1Filemage
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker to obtain sensitive information via a crafted request to the /mgmt/ component.
1Yealink
1W60b Firmware
Jun 17, 2026
Aug 22, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Directory Traversal vulnerability in Contacts File Upload Interface in Yealink W60B version 77.83.0.85, allows attackers to gain sensitive information and cause a denial of service (DoS).
1Ziahamza
1Webui Aria2
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
1Arubanetworks
1Edgeconnect Sd Wan Orchestrator
Jun 17, 2026
Aug 22, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to ex...Show more
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.Show less
1Danfoss
1Ak Sm 800a Firmware
Jun 17, 2026
Aug 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
1Typora
1Typora
Jun 17, 2026
Aug 19, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be expl...Show more
Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.Show less
1Typora
1Typora
Jun 17, 2026
Aug 19, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be...Show more
Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora. Show less
1Obsidian
1Obsidian
Jun 17, 2026
Aug 19, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnera...Show more
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access local files and exfiltrate them to remote web servers via "app://local/<absolute-path>". This vulnerability can be exploited if a user opens a malicious markdown file in Obsidian, or copies text from a malicious webpage and paste it into Obsidian.Show less
1Jorani
1Jorani
Jun 17, 2026
Aug 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
1Rockwellautomation
1Thinmanager Thinserver
Jun 17, 2026
Aug 17, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the Thin...Show more
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed.  A malicious user could exploit this vulnerability by sending a crafted synchronization protocol message and potentially gain remote code execution abilities. Show less
1Rockwellautomation
1Thinmanager Thinserver
Jun 17, 2026
Aug 17, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a...Show more
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files with system privileges. A malicious user could exploit this vulnerability by sending a specifically crafted synchronization protocol message resulting in a denial-of-service condition. Show less