CWE-22
9,567 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,567)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Convert Svg Core Project 1Convert Svg Core Jun 17, 2026 Jan 21, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of package convert-svg-to-jpeg. Using a specially crafted SVG file, an attacker could read arbitrary files f...Show more |
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sending http://ip:port/../privacy.avi URL to compromise a victim's privacy. |
1Trendmicro 1Deep Security Agent Jun 17, 2026 Jan 20, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to read arbitrary files from the file system. Please note: a...Show more |
1Lexmark 2336500e Firmware B2236 FirmwareB2338 Firmware+230 moreJun 17, 2026 Jan 20, 2022 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files. |
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. |
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server. |
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable v...Show more |
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. In affected versions an adversary with a primitive that allows for filesys...Show more |
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special characters in URL parameters, which allows an unauthenticated local area network attacker to access restr...Show more |
4Debian FedoraprojectFlatpak+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jan 13, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At thi...Show more |
This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the server. |
Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present or not, resulting in a path traversal vulnerability allowing attackers with Item/Configure permissi...Show more |
1Jenkins 1Warnings Next Generation Jun 17, 2026 Jan 12, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-c...Show more |
1Bytecode Viewer Project 1Bytecode Viewer Jun 17, 2026 Jan 12, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited us...Show more |
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files. |
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files. |
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All versions < V10.3.3.3 only if web components are used), COMOS V10.3 (All versions >= V10.3.3.3 only if we...Show more |
An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information. |
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP PUT request. |
NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available. |