CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain...Show more |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 May 5, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 IBM QRadar SIEM 7.3 and 7.4 when decompressing or verifying signature of zip files processes data in a way that may be vulnerable to path traversal attacks. IBM X-Force ID: 192905. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 May 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names. |
BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achieve code execution. The attacker must craft a malicious plugin file with special characters to upload...Show more |
2Fedoraproject Secureauth2Fedora ImpacketJun 17, 2026 May 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This...Show more |
SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversal vulnerability due to insufficient input validation. Any admin config and file readable by the app...Show more |
1Zohocorp 1Manageengine Eventlog Analyzer Jun 17, 2026 Apr 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution. |
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php". |
1Cisco 1Firepower Threat Defense Jun 17, 2026 Apr 29, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques...Show more |
This vulnerability allows local attackers to delete arbitrary files on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code on the target gue...Show more |
1Novel Boutique House Plus Project 1Novel Boutique House Plus Jun 17, 2026 Apr 29, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Directory Traversal in the fileDownload function in com/java2nb/common/controller/FileController.java in Novel-plus (小说精品屋-plus) 3.5.1 allows attackers to read arbitrary files via the filePath parameter. |
1Buffalo 2Wsr 2533dhp3 Bk Firmware Wsr 2533dhpl2 Bk FirmwareJun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication. |
1Wpfastestcache 1Wp Fastest Cache Jun 17, 2026 Apr 27, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administrator privileges to delete arbitrary files on the server via unspecified vectors. |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Apr 27, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a UI-related folder via directory traversal (no customer-specific data is exposed). |
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md` files from the server's filesystem due to an improper input validation, which results in the abili...Show more |
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.0 through 14.4.2), and 3.0 prior to 5.0 (Vaadin 15 prior to 18) allows attacker to request arbitrary...Show more |
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component. |
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=". |
The Tutor LMS – eLearning and online course solution WordPress plugin before 1.8.8 is affected by a local file inclusion vulnerability through the maliciously constructed sub_page parameter of the plugin's Tools, allowin...Show more |
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importing a compromised project file to the affected software. Chained with other vulnera...Show more |