← Back
CWE-22

9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
1Command | Integration Suite For System Center
Jun 17, 2026
Aug 31, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to pe...Show more
Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system.Show less
1Carel
3Applica
Pcoweb Card FirmwarePcoweb Hvac Bacnet Gateway
Jun 17, 2026
Aug 31, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'fi...Show more
Carel pCOWeb HVAC BACnet Gateway 2.1.0, Firmware: A2.1.0 - B2.1.0, Application Software: 2.15.4A Software v16 13020200 suffers from an unauthenticated arbitrary file disclosure vulnerability. Input passed through the 'file' GET parameter through the 'logdownload.cgi' Bash script is not properly verified before being used to download log files. This can be exploited to disclose the contents of arbitrary and sensitive files via directory traversal attacks.Show less
1Fluxcd
1Flux2
Jun 17, 2026
Aug 31, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to deploy. Flux CLI allows users to deploy Flux...Show more
Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to deploy. Flux CLI allows users to deploy Flux components into a Kubernetes cluster via command-line. The vulnerability allows other applications to replace the Flux deployment information with arbitrary content which is deployed into the target Kubernetes cluster instead. The vulnerability is due to the improper handling of user-supplied input, which results in a path traversal that can be controlled by the attacker. Users sharing the same shell between other applications and the Flux CLI commands could be affected by this vulnerability. In some scenarios no errors may be presented, which may cause end users not to realize that something is amiss. A safe workaround is to execute Flux CLI in ephemeral and isolated shell environments, which can ensure no persistent values exist from previous processes. However, upgrading to the latest version of the CLI is still the recommended mitigation strategy.Show less
1Dell
1Container Storage Modules
Jun 17, 2026
Aug 30, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintenti...Show more
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.Show less
1Hitachi
1Hc Ip9100hd Firmware
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traversal via a crafted GET request to the endpoint /ptippage.cgi. Security i...Show more
Hitachi Kokusai Electric Newtork products for monitoring system (Camera, Decoder and Encoder) and below allows attckers to perform a directory traversal via a crafted GET request to the endpoint /ptippage.cgi. Security information ID hitachi-sec-2022-001 contains fixes for the issue.Show less
1Xplodedthemes
1Wpide
Jun 17, 2026
Aug 29, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue.
1Ingredient Stock Management System Project
1Ingredient Stock Management System
Jun 17, 2026
Aug 29, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
1Zaver Project
1Zaver
Jun 17, 2026
Aug 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Zaver through 2020-12-15 allows directory traversal via the GET /.. substring.
1Redhat
1Keycloak
Jun 17, 2026
Aug 26, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, th...Show more
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.Show less
1Redhat
1Jboss Core Services Httpd
Jun 17, 2026
Aug 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to ac...Show more
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
1Htmly
1Htmly
Jun 17, 2026
Aug 26, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php.
1Wuzhicms
1Wuzhicms
Jun 17, 2026
Aug 26, 2022
N/A· v4
2.7 LOW· v3
N/A· v2
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
1Rockwellautomation
1Isagraf Workbench
Jun 17, 2026
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF W...Show more
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF Workbench. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the ISaGRAF Workbench software. User interaction is required for this exploit to be successful.Show less
1Rockwellautomation
1Isagraf Workbench
Jun 17, 2026
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF...Show more
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running at the SYSTEM level, then the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.Show less
1Printerlogic
1Windows Client
Jun 17, 2026
Aug 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute mali...Show more
PrinterLogic Windows Client through 25.0.0.676 allows attackers to execute directory traversal. Authenticated users with prior knowledge of the driver filename could exploit this to escalate privileges or distribute malicious content. This issue has been resolved in PrinterLogic Windows Client 25.0.0688 and all affected are advised to upgrade.Show less
1Abb
1Zenon
Jun 17, 2026
Aug 24, 2022
N/A· v4
8.2 HIGH· v3
N/A· v2
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the...Show more
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities such as the start and stop of various activity and the last error code etc.Show less
1Xplodedthemes
1Wpide File Manager & Code Editor
Jun 17, 2026
Aug 23, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
1Taogogo
1Taocms
Jun 17, 2026
Aug 23, 2022
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt
1Pukiwiki
1Pukiwiki
Jun 17, 2026
Aug 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a malicious script via unspecified vectors.
1Wwbn
1Avideo
Jun 17, 2026
Aug 22, 2022
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can...Show more
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.Show less