CWE-22
9,562 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,562)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory. This issue affected Apache AsterixDB unreleased builds between commits 580b81aa5e8888b8e1b0620521a1...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. |
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is e...Show more |
1Magento 2Upward Connector Upward PhpJun 17, 2026 Feb 25, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Magento UPWARD-php version 1.1.4 (and earlier) is affected by a Path traversal vulnerability in Magento UPWARD Connector version 1.1.2 (and earlier) due to the upload feature. An attacker could potentially exploit this v...Show more |
1Vmware 2Cloud Foundation Vcenter ServerJun 17, 2026 Feb 24, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privile...Show more |
1Contec 1Sv Cpt Mc310 Firmware Jun 17, 2026 Feb 24, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or directories on the server via unspecified vectors. |
3Debian FedoraprojectMbsync Project4Debian Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '...Show more |
2Luxion Siemens6Keyshot Keyshot Network RenderingKeyshot Viewer+3 moreJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1...Show more |
1Nozominetworks 2Central Management Control GuardianJun 17, 2026 Feb 22, 2021 8.6 HIGH· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7...Show more |
1Atlassian 3Data Center Jira Data CenterJira ServerJun 17, 2026 Feb 22, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The CachingResourceDownloadRewriteRule class in Jira Server and Jira Data Center before version 8.5.11, from 8.6.0 before 8.13.3, and from 8.14.0 before 8.15.0 allowed unauthenticated remote attackers to read arbitrary f...Show more |
1Yeastar 1Neogate Tg400 Firmware Jul 9, 2026 Feb 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key. |
1Johnsoncontrols 1Metasys Reporting Engine Jun 17, 2026 Feb 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from the system. |
This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAction function of the CustomReportController class (bundles/AdminBundle/Controller/Reports/CustomRepor...Show more |
1Ibm 1Websphere Application Server Jun 17, 2026 Feb 18, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary fil...Show more |
Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal. |
A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated...Show more |
1Changjia Property Management System Project 1Changjia Property Management System Jun 17, 2026 Feb 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to download system files arbitrarily. |
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an authenticated directory traveral. |
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to gain remote code execution via the backup restore feature. To exploit the vulnerability, an attacker...Show more |
1Secomea 4Gatemanager 4250 Firmware Gatemanager 4260 FirmwareGatemanager 8250 Firmware+1 moreJun 17, 2026 Feb 15, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with administrative permissions to read and write arbitrary files in the Linux file system....Show more |