CWE-22
9,562 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,562)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreJun 17, 2026 Feb 11, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Path Traversal vulnerability. An unauthenticated attacker could leverage t...Show more |
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to read sensitive files. |
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authen...Show more |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw ex...Show more |
ftp-srv is an open-source FTP server designed to be simple yet configurable. In ftp-srv before version 4.4.0 there is a path-traversal vulnerability. Clients of FTP servers utilizing ftp-srv hosted on Windows machines ca...Show more |
1Sap 1Netweaver Master Data Management Server Jun 17, 2026 Feb 9, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exploit insufficient validation of path information provided by users, thus characters representing 'tr...Show more |
1Hp 1Moonshot Provisioning Manager Jun 17, 2026 Feb 9, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environmen...Show more |
1Siemens 2Sinec Network Management System Sinema ServerJun 17, 2026 Feb 9, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP1 Update 1), SINEMA Server (All versions < V14.0 SP2 Update 2). When uploading files to an affected system using a zip container, the system does no...Show more |
1Gradle 3Enterprise Test Distribution Agent MavenTest DistributionJun 17, 2026 Feb 9, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distribution-gradle-plugin before 1.3.2, and gradle-enterprise-maven-extension before 1.8.2. A malicious a...Show more |
1Hpe 1Baseboard Management Controller Jun 17, 2026 Feb 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletesolvideofile function. |
1Hpe 1Baseboard Management Controller Jun 17, 2026 Feb 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversal vulnerability in libifc.so webdeletevideofile function. |
2Fedoraproject Gnome2Fedora Gnome AutoarJun 17, 2026 Feb 5, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.5 HIGH· v3 9.4 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal a...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.5 HIGH· v3 9.4 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal a...Show more |
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. |
1Rainbowfishsoftware 1Pacsone Server Jun 17, 2026 Feb 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote information disclosure. |
3Debian DockerNetapp3Debian Linux DockerE Series Santricity Os ControllerJun 17, 2026 Feb 2, 2021 N/A· v4 6.8 MEDIUM· v3 2.7 LOW· v2 In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access to remapped root allows privilege escalation to real root. When using "--userns-remap", if the root...Show more |
loklak is an open-source server application which is able to collect messages from various sources, including twitter. The server contains a search index and a peer-to-peer index sharing interface. All messages are store...Show more |
IBM Content Navigator 3.0.CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on th...Show more |