CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Algosolutions 18373 Ip Zone Paging Adapter Firmware Jun 17, 2026 Jun 23, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Algo Communication Products Ltd. 8373 IP Zone Paging Adapter Firmware 1.7.6 allows attackers to perform a directory traversal via a web request sent to /fm-data.lua. |
1Devolutions 1Remote Desktop Manager Jun 17, 2026 Jun 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location. |
iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal. |
1Glpi Project 1Glpi Inventory Jun 17, 2026 Jun 20, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ### Workarounds `b/deploy/index.php` file can be deleted if deploy feature is not used. |
1Argo Events Project 1Argo Events Jun 17, 2026 Jun 17, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifac...Show more |
Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler. |
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2....Show more |
1Fast Food Ordering System Project 1Fast Food Ordering System Jun 17, 2026 Jun 14, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f=delete_img. |
1Tandd 2T&d Server Thermo Recorder Data Server FirmwareJun 17, 2026 Jun 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in T&D Data Server (Japanese Edition) Ver.2.22 and earlier, T&D Data Server (English Edition) Ver.2.30 and earlier, THERMO RECORDER DATA SERVER (Japanese Edition) Ver.2.13 and earlier, a...Show more |
Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX (<= 2.0.6) Themes allow logged-in users, including subscriber-level users, to perform Path Traversal and Local File inclusion. In the JupiterX theme, the jupite...Show more |
Directory traversal vulnerability in RCCMD 4.26 and earlier allows a remote authenticated attacker with an administrative privilege to read or alter an arbitrary file on the server via unspecified vectors. |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Jun 10, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticat...Show more |
1Dell 2Supportassist For Business Pcs Supportassist For Home PcsJun 17, 2026 Jun 10, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-adm...Show more |
1Convert Svg Project 1Convert Svg Jun 17, 2026 Jun 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package convert-svg-core before 0.6.4 are vulnerable to Directory Traversal due to improper sanitization of SVG tags. Exploiting this vulnerability is possible by using a specially crafted SVG file. |
1Thalesgroup 1Safenet Keysecure Jun 17, 2026 Jun 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows an authenticated user to read arbitrary files from the underlying system on which the product is de...Show more |
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
1Http File Server Project 1Http File Server Jun 17, 2026 Jun 9, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability that permits arbitrary directory listing, file read, and file write. |
1Django S3file Project 1Django S3file Jun 17, 2026 Jun 9, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 django-s3file is a lightweight file upload input for Django and Amazon S3 . In versions prior to 5.5.1 it was possible to traverse the entire AWS S3 bucket and in most cases to access or delete files. If the `AWS_LOCATIO...Show more |
1User Meta 1User Meta User Profile Builder And User Management Jun 17, 2026 Jun 8, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The User Meta WordPress plugin before 2.4.4 does not validate the filepath parameter of its um_show_uploaded_file AJAX action, which could allow low privileged users such as subscriber to enumerate the local files on the...Show more |