CWE-22
9,572 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,572)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Prasathmani 1Tiny File Manager Jun 17, 2026 Mar 15, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, le...Show more |
1Tipsandtricks Hq 1Simple Download Monitor Jun 17, 2026 Mar 14, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. |
An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving th...Show more |
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal. |
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.0...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 8.1 HIGH· v3 4.9 MEDIUM· v2 There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, f...Show more |
2Linuxfoundation Nats3Nats Server Nats ServerNats Streaming ServerJun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStream streams. nats-streaming-server before 0.24.3 is also affected. |
1Pfsense 1Pfsense Pkg Wireguard Jun 17, 2026 Mar 10, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0.1.6 versions prior to 0.1.6_1 allows a remote authenticated attacker to lead a...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/da/pcf" API. The affected endpoint does not h...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDiagnosticServlet has directory traversal vulnerability at the "/api/appInternals/1.0/agent/diagnostic/logs" API. The affected endp...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/agent/configuration" API. The affected e...Show more |
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icinga...Show more |
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to th...Show more |
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories. |
1Veritas 1Infoscale Operations Manager Jun 17, 2026 Mar 4, 2022 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch 100. The web server fails to sanitize admin/cgi-bin/rulemgr.pl/getfile/ input data, allowing a remo...Show more |
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. |
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the fil...Show more |
Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Ser...Show more |