← Back
CWE-22

9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,575)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
3Qts
Quts HeroQutscloud
Jun 17, 2026
May 5, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and...Show more
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Appliance. If exploited, this vulnerability allows attackers to read the contents of unexpected files and expose sensitive data. We have already fixed this vulnerability in the following versions of QuTScloud, QuTS hero, QTS, QVR Pro Appliance: QuTScloud c5.0.1.1949 and later QuTS hero h5.0.0.1949 build 20220215 and later QuTS hero h4.5.4.1951 build 20220218 and later QTS 5.0.0.1986 build 20220324 and later QTS 4.5.4.1991 build 20220329 and laterShow less
1Masacms
1Masacms
Jun 17, 2026
May 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.
1Bookeen
1Notea Firmware
Jul 9, 2026
May 5, 2022
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...Show more
In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06419017; Issue ID: ALPS06270870.Show less
1Google
1Android
Jun 17, 2026
May 3, 2022
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validatio...Show more
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as system user. The patch addresses incorrect implementation of file path validation check logic.Show less
1Clinical Genomics
1Scout
Jun 17, 2026
May 3, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
1Xwiki
1Xwiki
Jun 17, 2026
May 2, 2022
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against us...Show more
APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations on the filesystem. Writing an attacking script in Velocity requires the Script rights in XWiki so not all users can use it, and it also requires finding an XWiki API which returns a File. The problem has been patched in versions 12.6.7, 12.10.3, and 13.0. There is no easy workaround for fixing this vulnerability other than upgrading and being careful when giving Script rights.Show less
2Debian
Sinatrarb
2Debian Linux
Sinatra
Jun 17, 2026
May 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
1Nopcommerce
1Nopcommerce
Jun 17, 2026
May 2, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nopCommerce 4.50.1 is vulnerable to Directory Traversal via the backup file in the Maintenance feature.
1Pistache Project
1Pistache
Jun 17, 2026
May 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects the package pistacheio/pistache before 0.0.3.20220425. It is possible to traverse directories to fetch arbitrary files from the server.
1Alibabagroup
1One Java Agent
Jun 17, 2026
May 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g....Show more
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.Show less
1Glewlwyd Project
1Glewlwyd
Jun 17, 2026
Apr 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
static_compressed_inmemory_website_callback.c in Glewlwyd through 2.6.2 allows directory traversal.
1Piano Led Visualizer Project
1Piano Led Visualizer
Jun 17, 2026
Apr 29, 2022
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe fo...Show more
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call encounters an absolute path, it ignores all the parameters it has encountered till that point and starts working with the new absolute path. Since the "malicious" parameter represents an absolute path, the result of `os.path.join` ignores the static directory completely. Hence, untrusted input is passed via the `os.path.join` call to `flask.send_file` can lead to path traversal attacks. A patch with a fix is available on the `master` branch of the GitHub repository. This can also be fixed by preventing flow of untrusted data to the vulnerable `send_file` function. In case the application logic necessiates this behaviour, one can either use the `flask.safe_join` to join untrusted paths or replace `flask.send_file` calls with `flask.send_from_directory` calls.Show less
1Zohocorp
3Manageengine Access Manager Plus
Manageengine Pam360Manageengine Password Manager Pro
Jun 17, 2026
Apr 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProd...Show more
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDashboard. FetchEvents. and Synchronize) via the ../RestAPI substring.Show less
1Smartptt
1Smartptt Scada
Jun 17, 2026
Apr 28, 2022
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from t...Show more
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.Show less
1Franklinfueling
1Ts 550 Evo Firmware
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
1Franklinfueling
1Ts 550 Evo Firmware
Jun 17, 2026
Apr 27, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
1Dhcms Project
1Dhcms
Jun 17, 2026
Apr 26, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
dhcms v20170919 was discovered to contain an arbitrary folder deletion vulnerability via /admin.php?r=admin/AdminBackup/del.
1Hongcms Project
1Hongcms
Jun 17, 2026
Apr 26, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
HongCMS 3.0.0 allows arbitrary file deletion via the component /admin/index.php/template/ajax?action=delete.
1Verydows
1Verydows
Jun 17, 2026
Apr 26, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Verydows v2.0 was discovered to contain an arbitrary file deletion vulnerability via \backend\database_controller.php.