CWE-22
9,563 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,563)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Asus 44Asmb9 Ikvm Firmware E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 moreJun 17, 2026 Apr 6, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path...Show more |
1Asus 44Asmb9 Ikvm Firmware E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 moreJun 17, 2026 Apr 6, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path tra...Show more |
1Asus 44Asmb9 Ikvm Firmware E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 moreJun 17, 2026 Apr 6, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path trav...Show more |
1Asus 44Asmb9 Ikvm Firmware E700 G4 FirmwareEsc4000 Dhd G4 Firmware+41 moreJun 17, 2026 Apr 6, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of path...Show more |
1Asus 3Asmb8 Ikvm Firmware Z10pe D16 Ws FirmwareZ10pr D16 FirmwareJun 17, 2026 Apr 6, 2021 N/A· v4 4.9 MEDIUM· v3 6.8 MEDIUM· v2 The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can use the means of p...Show more |
Directory traversal in coreframe/app/template/admin/index.php in WUZHI CMS 4.1.0 allows attackers to list files in arbitrary directories via the dir parameter. |
Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash. |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Apr 1, 2021 N/A· v4 9.1 CRITICAL· v3 9.4 HIGH· v2 Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path traversal issue in spark gateway component. This allows a remote attacker to remotely delete any direct...Show more |
1Netgear 1Prosafe Network Management System Jun 17, 2026 Mar 29, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the...Show more |
1Netgear 1Prosafe Network Management System Jun 17, 2026 Mar 29, 2021 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 This vulnerability allows remote attackers to disclose sensitive information and delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required...Show more |
1Netgear 1Prosafe Network Management System Jun 17, 2026 Mar 29, 2021 N/A· v4 7.1 HIGH· v3 7.5 HIGH· v2 This vulnerability allows remote attackers to delete arbitrary files on affected installations of NETGEAR ProSAFE Network Management System 1.6.0.26. Although authentication is required to exploit this vulnerability, the...Show more |
1Gitjacker Project 1Gitjacker Jun 17, 2026 Mar 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal. |
1Linuxfoundation 1Container Network Interface Jun 17, 2026 Mar 26, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying the plugin to load in the 'type' field in the network configuration, it is possible to use special e...Show more |
1Invigo 1Automatic Device Management Jun 17, 2026 Mar 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application. |
1Invigo 1Automatic Device Management Jun 17, 2026 Mar 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the...Show more |
Path Traversal vulnerability in Samsung Notes prior to version 4.2.00.22 allows attackers to access local files without permission. |
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0-rc1, it is possible for path traversal to occur with DAGs containing relative...Show more |
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. This vulnerabilit...Show more |
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject arbitrary commands that can be executed as the root user. This vulnerability is due to insufficient input val...Show more |
A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticated, remote attacker to conduct directory traversal attacks and read and write files on the underlying...Show more |