CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access to sensitive information. |
1Dell 1Supportassist Client Consumer Jun 17, 2026 Sep 28, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. S...Show more |
Dell NetWorker, versions 18.x and 19.x contain a Path traversal vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and gain access to unauthorized in...Show more |
1Sonicwall 5Sma 200 Firmware Sma 210 FirmwareSma 400 Firmware+2 moreJun 17, 2026 Sep 27, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An improper access control vulnerability in SMA100 allows a remote unauthenticated attacker to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings. |
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF. |
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression. |
An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution via uploaded PHP code, related to the bFilename parameter. |
1Speed Test Project 1Speed Test Jun 17, 2026 Sep 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET /.." substring. |
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restri...Show more |
Payara Micro Community 5.2021.6 and below allows Directory Traversal. |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The vCenter Server contains a file path traversal vulnerability leading to information disclosure in the appliance management API. A malicious actor with network access to port 443 on vCenter Server may exploit this issu...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Sep 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by...Show more |
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected versions authenticated attackers posing as functionaries (i.e., within a trusted set of users for a l...Show more |
The OMGF WordPress plugin before 4.5.4 does not enforce path validation, authorisation and CSRF checks in the omgf_ajax_empty_dir AJAX action, which allows any authenticated users to delete arbitrary files or folders on...Show more |
The OMGF WordPress plugin before 4.5.4 does not escape or validate the handle parameter of the REST API, which allows unauthenticated users to perform path traversal and overwrite arbitrary CSS file with Google Fonts CSS...Show more |
1Tubitak 1Pardus Software Center Jun 17, 2026 Sep 18, 2021 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 A path traversal vulnerability on Pardus Software Center's "extractArchive" function could allow anyone on the same network to do a man-in-the-middle and write files on the system. |
1Cmsmadesimple 1Cms Made Simple Jun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in CMS Made Simple 2.2.8. It is possible to achieve unauthenticated path traversal in the CGExtensions module (in the file action.setdefaulttemplate.php) with the m1_filename parameter; and throug...Show more |
1Sharpcompress Project 1Sharpcompress Jun 17, 2026 Sep 16, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 are vulnerable to partial path traversal. SharpCompress recreates a hierarchy of directories under des...Show more |
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter. |
SAP Cloud Connector, version - 2.0, allows the upload of zip files as backup. This backup file can be tricked to inject special elements such as '..' and '/' separators, for attackers to escape outside of the restricted...Show more |