← Back
CWE-22

9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Seeddms
1Seeddms
Jun 17, 2026
Jun 6, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbi...Show more
SeedDMS 6.0.17 and 5.1.24 are vulnerable to Directory Traversal. The "Remove file" functionality inside the "Log files management" menu does not sanitize user input allowing attackers with admin privileges to delete arbitrary files on the remote system.Show less
1Grafana
1Grafana
Jun 17, 2026
Jun 6, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; thi...Show more
Grafana 8.4.3 allows reading files via (for example) a /dashboard/snapshot/%7B%7Bconstructor.constructor'/.. /.. /.. /.. /.. /.. /.. /.. /etc/passwd URI. NOTE: the vendor's position is that there is no vulnerability; this request yields a benign error page, not /etc/passwd contentShow less
2Carrier
Hidglobal
14Ep4502 Firmware
Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 more
Jun 17, 2026
Jun 6, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury In...Show more
An authenticated attacker can upload a file with a filename including “..” and “/” to achieve the ability to upload the desired file anywhere on the filesystem. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.271. This allows a malicious actor to overwrite sensitive system files and install a startup service to gain remote access to the underlaying Linux operating system with root privileges.Show less
1Realnetworks
1Realplayer
Jun 17, 2026
Jun 3, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in t...Show more
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).Show less
1Solutions Atlantic
1Regulatory Reporting System
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/Sh...Show more
Solutions Atlantic Regulatory Reporting System (RRS) v500 is vulnerable to Local File Inclusion (LFI). Any authenticated user has the ability to reference internal system files within requests made to the RRSWeb/maint/ShowDocument/ShowDocument.aspx page. The server will successfully respond with the file contents of the internal system file requested. This ability could allow for adversaries to extract sensitive data and/or files from the underlying file system, gain knowledge about the internal workings of the system, or access source code of the application.Show less
1Elitecms
1Elite Cms
Jun 17, 2026
Jun 2, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
1Webbank
1Webcube
Jul 9, 2026
Jun 2, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
1Keysight
2N6841a Rf Firmware
N6854a Firmware
Jun 17, 2026
Jun 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.
1Mend
1Curekit
Jun 17, 2026
May 31, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.
1Dedecms
1Dedecms
Jun 17, 2026
May 26, 2022
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
2Debian
Netapp
3Debian Linux
DpkgOntap Select Deploy Administration Utility
Jun 17, 2026
May 26, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3...Show more
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.Show less
1Xwiki
1Xwiki
Jun 17, 2026
May 25, 2022
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the clas...Show more
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the template API and a path with ".." in it. The issue is patched in versions 14.0 and 13.10.3. There is no easy workaround for this issue.Show less
1Ginadmin Project
1Ginadmin
Jun 17, 2026
May 25, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In ginadmin through 05-10-2022 the incoming path value is not filtered, resulting in directory traversal.
1Hashicorp
1Go Getter
Jun 17, 2026
May 25, 2022
N/A· v4
8.6 HIGH· v3
7.5 HIGH· v2
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
1Aggsoft
1Webserver
Jun 17, 2026
May 24, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system.
1Filegator
1Filegator
Jun 17, 2026
May 24, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Path Traversal in GitHub repository filegator/filegator prior to 7.8.0.
1Gitblit
1Gitblit
Jun 17, 2026
May 21, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname).
1Cambiumnetworks
1Cnmaestro
Jun 17, 2026
May 17, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../...Show more
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../) as part of a filename, the server will save the file where the attacker chooses. This could allow an attacker to write any data to any file in the server.Show less
1Dlink
1Dir 825 Firmware
Jun 17, 2026
May 17, 2022
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entir...Show more
D-LINK DIR-825 AC1200 R2 is vulnerable to Directory Traversal. An attacker could use the "../../../../" setting of the FTP server folder to set the router's root folder for FTP access. This allows you to access the entire router file system via the FTP server.Show less
1Cmseasy
1Cmseasy
Jun 17, 2026
May 17, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerabi...Show more
cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script file is written to the website server, and accessing this file can lead to a code execution vulnerability.Show less