CWE-22
9,562 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,562)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back sla...Show more |
2Opensuse Sylabs3Backports Sle LeapSingularityJun 17, 2026 Oct 14, 2020 N/A· v4 9.3 CRITICAL· v3 5.8 MEDIUM· v2 Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of path traversal and the lack of path sanitization within `unsquashfs`, it is possible to ov...Show more |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Oct 12, 2020 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can traverse up the file system to get access to content on disk (that the user runn...Show more |
HUAWEI P30 Pro versions earlier than 10.1.0.160(C00E160R2P8) have a path traversal vulnerability. The system does not sufficiently validate certain pathname, successful exploit could allow the attacker access files and c...Show more |
1Ibm 1Curam Social Program Management Jun 17, 2026 Oct 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A path traversal vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10, which could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted file p...Show more |
A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is...Show more |
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the runner is configured on a Windows system with a docker executor, which allows the attacker to run ar...Show more |
MonoCMS Blog 1.0 is affected by: Arbitrary File Deletion. Any authenticated user can delete files on and off the webserver (php files can be unlinked and not deleted). |
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows directory traversal for an unprivileged process to read arbitrary files. The Samsung ID is SVE-2020-18433...Show more |
1Xmpp Http Upload Project 1Xmpp Http Upload Jun 17, 2026 Oct 6, 2020 N/A· v4 3.5 LOW· v3 4.0 MEDIUM· v2 In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Informati...Show more |
1Whatsapp 2Whatsapp Whatsapp BusinessJun 17, 2026 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pp...Show more |
1Szuray 2Iptv/h.264 Video Encoder Firmware Iptv/h.265 Video Encoder FirmwareJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthenticated HTTP requests to exploit path traversal and pattern-matching programming flaws, and retrieve an...Show more |
In Wiki.js before version 2.5.151, directory traversal outside of Wiki.js context is possible when a storage module with local asset cache fetching is enabled. A malicious user can potentially read any file on the file s...Show more |
Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is...Show more |
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimpleCMS-3.3.15/admin/log.php |
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/upload-profile-picture. |
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used. |
1Teltonika Networks 1Trb245 Firmware Jun 17, 2026 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to read the contents of arbitrary files on disk. |
1Teltonika Networks 1Trb245 Firmware Jun 17, 2026 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/system/admin/certificates/delete action. |
1Teltonika Networks 1Trb245 Firmware Jun 17, 2026 Oct 1, 2020 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 Relative Path Traversal in Teltonika firmware TRB2_R_00.02.04.3 allows a remote, authenticated attacker to delete arbitrary files on disk via the admin/services/packages/remove action. |