CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_file is used with extract=True. NOTE: the vendor's position is that tf.keras.utils.get_file is not inte...Show more |
1Webport Cms Project 1Webport Cms Jun 17, 2026 Jun 28, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Directory Traversal vulnerability in Webport CMS 1.19.10.17121 via the file parameter to file/download. |
Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrar...Show more |
Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal vulnerability when creating a store with child theme.Successful exploitation could lead to arbitrar...Show more |
Adobe Illustrator version 25.2 (and earlier) is affected by a Path Traversal vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code ex...Show more |
Adobe InCopy version 16.0 (and earlier) is affected by an path traversal vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve remote code execution in the co...Show more |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Jun 28, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during...Show more |
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings. |
1Synology 2Diskstation Manager Diskstation Manager Unified ControllerJun 17, 2026 Jun 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allows remote attackers to write arbitrary files...Show more |
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation. |
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system. |
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on...Show more |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Jun 18, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content of a blob file (via a GET request) without having been granted access. |
Directory Traversal vulnerability in phpCMS 9.1.13 via the q parameter to public_get_suggest_keyword. |
bloofoxCMS 0.5.2.1 is infected with Path traversal in the 'fileurl' parameter that allows attackers to read local files. |
LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled manner. This deletion is possible via direc...Show more |
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands o...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Jun 11, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file...Show more |
1Whatsapp 2Whatsapp Whatsapp BusinessJun 17, 2026 Jun 11, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for Android v2.21.8.13 could have allowed path traversal attacks that overwrite WhatsApp files. |
LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal. |