CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and...Show more |
MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. |
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information. |
In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...Show more |
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validatio...Show more |
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. |
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against us...Show more |
2Debian Sinatrarb2Debian Linux SinatraJun 17, 2026 May 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. |
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature. |
This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server. |
1Alibabagroup 1One Java Agent Jun 17, 2026 May 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g....Show more |
static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal. |
1Piano Led Visualizer Project 1Piano Led Visualizer Jun 17, 2026 Apr 29, 2022 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe fo...Show more |
1Zohocorp 3Manageengine Access Manager Plus Manageengine Pam360Manageengine Password Manager ProJun 17, 2026 Apr 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProd...Show more |
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from t...Show more |
1Franklinfueling 1Ts 550 Evo Firmware Jun 17, 2026 Apr 27, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information. |
1Franklinfueling 1Ts 550 Evo Firmware Jun 17, 2026 Apr 27, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information. |
dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del. |
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete. |
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php. |