CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file deletion. An attack...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to FsTFtp file overwrite. An attacker can ma...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FsTFtp functionality of Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU). A specially crafted HTTP request can lead to arbitrary file overwrite FsTFtp file disc...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FSBrowsePage functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to information disclosure. An attacker can make...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FsMove functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially crafted HTTP request can lead to local file inclusion. An attacker can make an authe...Show more |
1Lantronix 1Premierwave 2050 Firmware Jun 17, 2026 Dec 22, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A directory traversal vulnerability exists in the Web Manager FsCopyFile functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to local file inclusion. An attacker can make an a...Show more |
A directory traversal vulnerability exists in the Web Manager File Upload functionality of Lantronix PremierWave 2050 8.9.0.0R4. A specially-crafted HTTP request can lead to arbitrary file overwrite. An attacker can make...Show more |
1Starcharge 2Nova 360 Cabinet Firmware Titan 180 Premium FirmwareJul 9, 2026 Dec 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0. |
1Chinasea 1Qb Smart Service Robot Jun 17, 2026 Dec 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Chain Sea ai chatbot system’s specific file download function has path traversal vulnerability. The function has improper filtering of special characters in URL parameters, which allows a remote attacker to download arbi...Show more |
1Http Server Node Project 1Http Server Node Jun 17, 2026 Dec 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is. |
message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message bus with diagnostics features enabled (default off) are vulnerable to a path traversal bug, which c...Show more |
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the pathname of the emulator and use path traversal to run an arbitrary executable located on the host system. When the user starts the emulator from SOPA...Show more |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances....Show more |
Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to r...Show more |
Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. Fi...Show more |
1Hd Network Real Time Monitoring System Project 1Hd Network Real Time Monitoring System Jun 17, 2026 Dec 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter. |
SAF-T Framework Transaction SAFTN_G allows an attacker to exploit insufficient validation of path information provided by normal user, leading to full server directory access. The attacker can see the whole filesystem st...Show more |
The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/re...Show more |
taocms 3.0.2 is vulnerable to arbitrary file deletion via taocms\include\Model\file.php from line 60 to line 72. |
1Siemens 1Simatic Easie Pcs 7 Skill Jun 17, 2026 Dec 14, 2021 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading files, the affected systems do not properly neutralize special elements within the pathname. An attac...Show more |