CWE-22
9,567 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,567)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in helmTemplate in repository.go. For example, an attacker may be able to discover credentials stored in a...Show more |
1Globalnorthstar 1Northstar Club Management Jun 17, 2026 Feb 4, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to browse and list the directories across the...Show more |
1Globalnorthstar 1Northstar Club Management Jun 17, 2026 Feb 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the...Show more |
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. |
mozilo2.0 was discovered to be vulnerable to directory traversal attacks via the parameter curent_dir. |
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow...Show more |
Path Traversal in NPM w-zip prior to 1.0.12. |
1Wpdeveloper 1Essential Addons For Elementor Jun 17, 2026 Feb 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File I...Show more |
1Bestwebsoft 1Error Log Viewer Jun 17, 2026 Feb 1, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary...Show more |
Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create a new thread/post with an include referencing a file local to the host operating system. Nimforum wi...Show more |
The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the ZipFile::uncompressEntry function in juce_ZipFile.cpp. This vulnerability is triggered when th...Show more |
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php. |
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau file on the operating system without preventing %2e%2e%5c directory traversal. |
1Zip Local Project 1Zip Local Jun 17, 2026 Jan 28, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory. |
SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at unauthorized access to the file system. on the "Name" parameter the attacker can return to the root...Show more |
1Sharpziplib Project 1Sharpziplib Jun 17, 2026 Jan 26, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a check was added if the destination file is under destination directory. However, it is not enforced tha...Show more |
1Sharpziplib Project 1Sharpziplib Jun 17, 2026 Jan 26, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a check was added if the destination file is under a destination directory. However, it is not enforced t...Show more |
1Sharpziplib Project 1Sharpziplib Jun 17, 2026 Jan 26, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` may be extracted in the parent directory of `destFolder`. This leads to arbitrary file write that may...Show more |
Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out of expected folder. The risk is low as obr:* commands are not very used and the entry is set by use...Show more |
1Telosalliance 1Z/ip One Firmware Jun 17, 2026 Jan 24, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, passwo...Show more |