← Back
CWE-22

9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Synology
1Webdav Server
Jun 17, 2026
Jul 28, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via...Show more
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology WebDAV Server before 2.4.0-0062 allows remote authenticated users to delete arbitrary files via unspecified vectors.Show less
1Synology
1Dns Server
Jun 17, 2026
Jul 28, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspe...Show more
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synology DNS Server before 2.2.2-5027 allows remote authenticated users to delete arbitrary files via unspecified vectors.Show less
1Helpsystems
1Goanywhere Managed File Transfer
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a...Show more
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.Show less
1Jenkins
1Deployer Framework
Jun 17, 2026
Jul 27, 2022
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an at...Show more
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementing form validation, allowing attackers with Item/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.Show less
1Jenkins
1Deployer Framework
Jun 17, 2026
Jul 27, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitra...Show more
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the application path of the applications when configuring a deployment, allowing attackers with Item/Configure permission to upload arbitrary files from the Jenkins controller file system to the selected service.Show less
1Sims Project
1Sims
Jun 17, 2026
Jul 27, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Sims v1.0 was discovered to allow path traversal when downloading attachments.
1Synology
1Diskstation Manager
Jun 17, 2026
Jul 27, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitr...Show more
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25423 allows remote authenticated users to delete arbitrary files via unspecified vectors.Show less
1Pandorafms
1Pandora Fms
Jun 17, 2026
Jul 26, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The i...Show more
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running application privilege.Show less
1Qr Code Generator Project
1Qr Code Generator
Jul 9, 2026
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Jul 25, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker...Show more
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.Show less
1Snyk
1Broker
Jun 17, 2026
Jul 25, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
1Tecrail
1Responsive Filemanager
Nov 21, 2024
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the pub...Show more
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended to upgrade the affected component.Show less
1Google
1Chrome
Jun 17, 2026
Jul 23, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
1Advantech
1Iview
Jun 17, 2026
Jul 22, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code.
2Debian
Tzinfo Project
2Debian Linux
Tzinfo
Jun 17, 2026
Jul 22, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinf...Show more
TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinfo-data, are vulnerable to relative path traversal. With the Ruby data source, time zones are defined in Ruby files. There is one file per time zone. Time zone files are loaded with `require` on demand. In the affected versions, `TZInfo::Timezone.get` fails to validate time zone identifiers correctly, allowing a new line character within the identifier. With Ruby version 1.9.3 and later, `TZInfo::Timezone.get` can be made to load unintended files with `require`, executing them within the Ruby process. Versions 0.3.61 and 1.2.10 include fixes to correctly validate time zone identifiers. Versions 2.0.0 and later are not vulnerable. Version 0.3.61 can still load arbitrary files from the Ruby load path if their name follows the rules for a valid time zone identifier and the file has a prefix of `tzinfo/definition` within a directory in the load path. Applications should ensure that untrusted files are not placed in a directory on the load path. As a workaround, the time zone identifier can be validated before passing to `TZInfo::Timezone.get` by ensuring it matches the regular expression `\A[A-Za-z0-9+\-_]+(?:\/[A-Za-z0-9+\-_]+)*\z`.Show less
1Givewp
1Givewp
Jun 17, 2026
Jul 21, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.20.2 at WordPress.
1Abb
7Rmc 100 Lite Firmware
Rmc 100 FirmwareUdc Firmware+4 more
Jun 17, 2026
Jul 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller pro...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an attacker who successfully exploited this vulnerability could insert and run arbitrary code in an affected system node.Show less
1Iconics
1Genesis64
Jun 17, 2026
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10...Show more
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1 allows a remote unauthenticated attacker to access to arbitrary files in the GENESIS64 server or ICONICS suite server and disclose information stored in the files by embedding a malicious URL parameter in the URL of the monitoring screen delivered to the GENESIS64 or ICONICS Suite mobile monitoring application and accessing the monitoring screen.Show less
1Inductiveautomation
1Ignition
Jun 17, 2026
Jul 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.
1Goldshell
1Goldshell Miner Firmware
Jun 17, 2026
Jul 20, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Goldshell ASIC Miners v2.2.1 and below was discovered to contain a path traversal vulnerability which allows unauthenticated attackers to retrieve arbitrary files from the device.