CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticated J-web user to read sensitive system files. This issue affects Juniper Networks Junos OS on SRX and vSRX Series: 19.3 v...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker must first obtain the ability to execute high-privileged code on the target guest...Show more |
AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution. |
There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to v...Show more |
Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is able to read local files from the server that can disclose important information. As a workaround, a...Show more |
1Sonicwall 11Email Security Email Security Appliance 3300 FirmwareEmail Security Appliance 4300 Firmware+8 moreJun 17, 2026 Apr 20, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. |
A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vulnerability in FBX’s Review causing it to run arbitrary code on the system. |
1Schneider Electric 1C Bus Toolkit Jun 17, 2026 Apr 13, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring a project. |
1Schneider Electric 1C Bus Toolkit Jun 17, 2026 Apr 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when a file is uploaded. |
1Schneider Electric 1C Bus Toolkit Jun 17, 2026 Apr 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when restoring project files. |
1Schneider Electric 1C Bus Toolkit Jun 17, 2026 Apr 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in C-Bus Toolkit (V1.15.7 and prior) that could allow a remote code execution when processing config files. |
4Apache DebianNetapp+1 more60Access Manager Active Iq Unified ManagerAgile Engineering Data Management+57 moreJun 17, 2026 Apr 13, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files...Show more |
A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT token |
An improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary files of system process via untrusted applications. |
Directory traversal vulnerability in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the path parameter to wex/cssjs.php. |
Directory traversal in Wcms 0.3.2 allows an attacker to read arbitrary files on the server that is running an application via the pagename parameter to wex/html.php. |
1Eikisoft 1Archive Collectively Operation Utility Jun 17, 2026 Apr 7, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker to create or overwrite files by leading a user to expand a malicious ZIP archives. |
OpenIAM before 4.2.0.3 allows Directory Traversal in the Batch task. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Apr 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via uploaded files with suitably crafted file names. Built-in upload handlers were not affected by this vu...Show more |
There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers can access credential data with this leakage. |