CWE-22
9,572 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,572)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Passwork On-Premise Edition before 4.6.13 allows migration/uploadExportFile Directory Traversal (to upload files). |
Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files). |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal vulnerability, allowing a malic...Show more |
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal bug, compounded by an improper...Show more |
1Rockwellautomation 1Connected Components Workbench Jun 17, 2026 Mar 23, 2022 N/A· v4 8.2 HIGH· v3 6.9 MEDIUM· v2 Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip...Show more |
1Rockwellautomation 1Connected Components Workbench Jun 17, 2026 Mar 23, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Component...Show more |
1Cyclonedx 1Bill Of Materials Repository Server Jun 17, 2026 Mar 22, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading...Show more |
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. |
connector.minimal.php in std42 elFinder through 2.1.60 is affected by path traversal. This allows unauthenticated remote attackers to read, write, and browse files outside the configured document root. This is due to imp...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not ch...Show more |
2Igniterealtime Pascom2Cloud Phone System OpenfireJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Mar 17, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code. |
The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in t...Show more |
1Prasathmani 1Tiny File Manager Jun 17, 2026 Mar 17, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7. |
1Ptc 2Axeda Agent Axeda Desktop ServerJun 17, 2026 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) (disregarding Axeda agent v6.9.2 and v6.9.3) is vulnerable to directory traversal, which could allow a remo...Show more |
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and session cookie to manually upload files to any location that the operating system user account under wh...Show more |
The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL. |
1Jenkins 1Kubernetes Continuous Deploy Jun 17, 2026 Mar 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read arbitrary files on the Jenkins controller. |
1Jenkins 1Extended Choice Parameter Jun 17, 2026 Mar 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission to read values from arbitrary JSON and Java properties files on the Jenkins controller. |
1Tibco 2Jasperreports Library Jasperreports ServerJun 17, 2026 Mar 15, 2022 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 The Server component of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports...Show more |