CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Prasathmani 1Tiny File Manager Jun 17, 2026 Sep 15, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter...Show more |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'FileManager.editFile()' function in the component 'modules/filemanager/FileManagerController.java'...Show more |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information or cause a denial of service via the 'FileManager.delete()' function in the component 'modules/filemanager/...Show more |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the 'getFolder()' function in the component '/modules/filemanager/FileManager.java'. |
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the 'TemplatePath' parameter in the component 'jfinal_cms/admin/folder/list'. |
1Microsoft 17Windows 10 1507 Windows 10 1607Windows 10 1809+14 moreJun 17, 2026 Sep 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 <p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using speciall...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Sep 14, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to a...Show more |
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing,...Show more |
SAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the contents of index in the directory, which would otherwise be restricted to high privi...Show more |
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or directories that are outside of the restricted directory. A successful attack allows access to high leve...Show more |
1Siemens 1Teamcenter Active Workspace Jun 17, 2026 Sep 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability has been identified in Teamcenter Active Workspace V4.3 (All versions < V4.3.10), Teamcenter Active Workspace V5.0 (All versions < V5.0.8), Teamcenter Active Workspace V5.1 (All versions < V5.1.5), Teamce...Show more |
1Siemens 1Sinec Network Management System Jun 17, 2026 Sep 14, 2021 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1). An attacker with access to the webserver of an affected system could download arbitrary files from the underlying filesystem by sending a specia...Show more |
2Debian Squashfs Tools Project2Debian Linux Squashfs ToolsJun 17, 2026 Sep 14, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to include a symbolic link and then contents u...Show more |
1Wp Publications Project 1Wp Publications Jun 17, 2026 Sep 10, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in the ~/bibtexbrowser.php file which allows attackers to include local zip files and achieve remote c...Show more |
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform permanent denial of service on the device. |
Path traversal vulnerability in FactoryAirCommnadManger prior to SMR Sep-2021 Release 1 allows attackers to write file as system uid via remote socket. |
1Apple 5Ipados Iphone OsMacos+2 moreJun 17, 2026 Sep 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5. A local user may be able to mod...Show more |
1Apple 6Ipados Iphone OsMac Os X+3 moreJun 17, 2026 Sep 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11...Show more |
1Apple 6Ipados Iphone OsMac Os X+3 moreJun 17, 2026 Sep 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iOS 14.5 and iPadOS 14.5, watchOS...Show more |
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories. |