CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Unified Communications Manager Jun 17, 2026 Jul 6, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated...Show more |
1Cisco 2Expressway Telepresence Video Communication ServerJun 17, 2026 Jul 6, 2022 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Multiple vulnerabilities in the API and in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow a remote attacker to overwrite arbitrary files...Show more |
1Cisco 2Unified Communications Manager Unified Communications Manager Im And Presence ServiceJun 17, 2026 Jul 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Man...Show more |
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk. |
1Zohocorp 1Manageengine Servicedesk Plus Msp Jun 17, 2026 Jul 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zoho ManageEngine ServiceDesk Plus MSP before 10604 allows path traversal (to WEBINF/web.xml from sample/WEB-INF/web.xml or sample/META-INF/web.xml). |
A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of...Show more |
A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f...Show more |
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitrary files via a directory traversal. |
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files. |
1Album Lock Project 1Album Lock Nov 21, 2024 Jun 27, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. The manipulation of the argument filePaht leads to path traversal. Attac...Show more |
1Product Configurator For Woocommerce Project 1Product Configurator For Woocommerce Jun 17, 2026 Jun 27, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is bein...Show more |
1Dell 1Wyse Management Suite Jun 17, 2026 Jun 24, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesyste...Show more |
1Concretecms 1Concrete Cms Jun 17, 2026 Jun 24, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Concrete 8.5.7 and below as well as Concrete 9.0 through 9.0.2 allow traversal in /index.php/ccm/system/file/upload which could result in an Arbitrary File Delete exploit. This was remediated by sanitizing /index.php/ccm...Show more |
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow...Show more |
OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remo...Show more |
LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure. |
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. |
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restrictions of the user running the FTP serv...Show more |
1Jenkins 1Embeddable Build Status Jun 17, 2026 Jun 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path tr...Show more |
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without...Show more |