← Back
CWE-22

9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Metersphere
1Metersphere
Jun 17, 2026
Dec 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validat...Show more
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.Show less
1Elvexys
1Streamx
Jun 17, 2026
Dec 29, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web serv...Show more
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented authentication scheme. StreamX applications using StreamView HTML component with the public web server feature activated are affected. Show less
1Elvexys
1Streamx
Jun 17, 2026
Dec 29, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authenticated users to get unauthorized access to files on the server's filesystem. StreamX applications us...Show more
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authenticated users to get unauthorized access to files on the server's filesystem. StreamX applications using StreamView HTML component with the public web server feature activated are affected.Show less
1Huawei
1Aslan Al10 Firmware
Jun 17, 2026
Dec 28, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Huawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access or modify protected system resources.
1Esri
1Arcgis Server
Jun 17, 2026
Dec 28, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intend...Show more
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may allow a remote, unauthenticated attacker traverse the file system to access files outside of the intended directory on ArcGIS Server. This could lead to the disclosure of sensitive site configuration information (not user datasets).Show less
1Cloudsync Project
1Cloudsync
Jun 17, 2026
Dec 28, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnec...Show more
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnector.java. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is 3ad796833398af257c28e0ebeade68518e0e612a. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216919. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Widoco Project
1Widoco
Jun 17, 2026
Dec 27, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the file src/main/java/widoco/WidocoUtils.java. The manipulation leads to path traversal. It is possible t...Show more
A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the file src/main/java/widoco/WidocoUtils.java. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is f2279b76827f32190adfa9bd5229b7d5a147fa92. It is recommended to apply a patch to fix this issue. VDB-216914 is the identifier assigned to this vulnerability.Show less
1Tar Utils Project
1Tar Utils
Jun 17, 2026
Dec 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
1Unzip Project
1Unzip
Jun 17, 2026
Dec 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
1Go Unzip Project
1Go Unzip
Jun 17, 2026
Dec 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
1Aahframework
1Aah
Jun 17, 2026
Dec 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
1Goa.design
1Goa
Jun 17, 2026
Dec 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.
1Cloudfoundry
1Archiver
Apr 11, 2025
Dec 27, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
1Flatpress
1Flatpress
Jun 17, 2026
Dec 27, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Hand...Show more
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of the file fp-plugins/mediamanager/panels/panel.mediamanager.file.php of the component File Delete Handler. The manipulation of the argument deletefile leads to path traversal. The name of the patch is 5d5c7f6d8f072d14926fc2c3a97cdd763802f170. It is recommended to apply a patch to fix this issue. The identifier VDB-216861 was assigned to this vulnerability.Show less
1Httpserver Project
1Httpserver
Jun 17, 2026
Dec 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of...Show more
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri leads to path traversal: '../filedir'. The attack may be initiated remotely. The name of the patch is 1a0de56e4dafff9c2f9c8f6b130a764f7a50df52. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216863.Show less
1Philips
4Myvue
SpeechVue Motion+1 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
1Httpster Project
1Httpster
Jun 17, 2026
Dec 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been d...Show more
A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpathSync of the file src/server.coffee. The manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. The name of the patch is d3055b3e30b40b65d30c5a06d6e053dffa7f35d0. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-216748.Show less
1Android Processing Development Environment Project
1Android Processing Development Environment
Jun 17, 2026
Dec 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Ha...Show more
A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.Show less
1Planetestream
1Planet Estream
Jun 17, 2026
Dec 25, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
1Simmeth
1Lieferantenmanager
Jun 17, 2026
Dec 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an '"ImagesPath":"...Show more
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing an API call: /DS/LM_API/api/ConfigurationService/GetImages with an '"ImagesPath":"C:\\"' value.Show less