CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject The Fuck Project2Fedora The FuckJun 17, 2026 Jun 10, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature. |
Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may allow an unauthenticated user to potentially enable a denial of service via adjacent access. |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Jun 8, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary fi...Show more |
Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefoundation/Zope/security/advisories/GHSA-5pr9-v234-jw36 with additional cases of TAL expression travers...Show more |
This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality. |
2Dino Fedoraproject2Dino FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators. |
1Ibm 1Websphere Application Server Nd Jun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM WebSphere Application Server Network Deployment 8.5 and 9.0 could allow a remote authenticated attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (...Show more |
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter. |
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In `@backstage/techdocs-common` versions prior to 0.6.3, a malicious actor could...Show more |
2Eclipse Oracle9Banking Enterprise Default Management Banking PlatformCommunications Network Integrity+6 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. |
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management component in Synology Photo Station before 6.8.14-3500 allows remote authenticated users to write arbitrary...Show more |
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in Synology Docker before 18.09.0-0515 allows local users to read or write arbitrary file...Show more |
1Synology 1Diskstation Manager Jun 17, 2026 Jun 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to read limi...Show more |
Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows local users to execute arbitrary code via unspecified vector...Show more |
Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP URL paths in versions 1.18.2 and before. A remote attacker may craft a path with escaped slashes, e...Show more |
Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server when the `URL` scheme is not `file://`, and the URL points to a fetchable resource under its scheme and...Show more |
2Gnome Ytnef Project2Evolution YtnefNov 21, 2024 May 26, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitr...Show more |
1Schneider Electric 2Homelynk Firmware Spacelynk FirmwareJun 17, 2026 May 26, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a denial of service when an unauthorized fil...Show more |
1Ibm 38335 Gca Firmware 8335 Gta Firmware8335 Gtb FirmwareJun 17, 2026 May 25, 2021 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbitrary files on the sy...Show more |
MetInfo 7.0 beta is affected by a file modification vulnerability. Attackers can delete and modify ini files in app/system/language/admin/language_general.class.php and app/system/include/function/file.func.php. |