CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Path Traversal in WellKnownServlet in GitHub repository jgraph/drawio prior to 18.0.5. Read local files of the web application. |
1Amministrazione Aperta Project 1Amministrazione Aperta Jun 17, 2026 May 16, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Amministrazione Aperta WordPress plugin before 3.8 does not validate the open parameter before using it in an include statement, leading to a Local File Inclusion issue. The original advisory mentions that unauthenti...Show more |
OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary f...Show more |
mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories. |
1Blogengine 1Blogengine.net Jun 17, 2026 May 13, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 BlogEngine.NET v3.3.8.0 was discovered to contain an arbitrary file deletion vulnerability which allows attackers to delete files within the web server root directory via a crafted HTTP request. |
User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. When interacting in a normal matter with the Sametime chat application, users hold a cookie containin...Show more |
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/tinymce/examples/index.html" path. in the "Insert/Edit Embedded Media" window Choose Type : iFrame a...Show more |
1Contec 1Sv Cpt Mc310 Firmware Jun 17, 2026 May 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal. |
1Microstrategy 1Enterprise Manager Jun 17, 2026 May 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login...Show more |
ftcms <=2.1 was discovered to be vulnerable to Arbitrary File Read via tp.php |
ftcms <=2.1 was discovered to be vulnerable to directory traversal attacks via the parameter tp. |
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Delete vulnerability via the neirong parameter at \backend\controllers\DbController.php. |
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backend\controllers\DbController.php. |
1Servmask 1All In One Wp Migration Jun 17, 2026 May 10, 2022 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to insufficient file validation via the ~/lib/model/class-ai1wm-backups.php file, in versions up to, a...Show more |
2Debian Rarlab2Debian Linux UnrarAug 4, 2026 May 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR ar...Show more |
In Splunk Enterprise versions before 8.1.2, the uri path to load a relative resource within a web page is vulnerable to path traversal. It allows an attacker to potentially inject arbitrary content into the web page (e.g...Show more |
1Fluxcd 2Flux2 Kustomize ControllerJun 17, 2026 May 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to cause a Denial of Service at the controlle...Show more |
1Fluxcd 2Flux2 Kustomize ControllerJun 17, 2026 May 6, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerab...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 May 5, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, directory traversal vulnerabil...Show more |