← Back
CWE-22

9,561 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,561)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fast Http Project
1Fast Http
Jun 17, 2026
Jul 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects all versions of package fast-http. There is no path sanitization in the path provided at fs.readFile in index.js.
1Rollup Plugin Dev Server Project
1Rollup Plugin Dev Server
Jun 17, 2026
Jul 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects all versions of package rollup-plugin-dev-server. There is no path sanitization in readFile operation inside the readFileFromContentBase function.
1Rollup Plugin Server Project
1Rollup Plugin Server
Jun 17, 2026
Jul 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects all versions of package rollup-plugin-server. There is no path sanitization in readFile operation performed inside the readFileFromContentBase function.
1Marked Tree Project
1Marked Tree
Jun 17, 2026
Jul 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects all versions of package marked-tree. There is no path sanitization in the path provided at fs.readFile in index.js.
1Indo Mars
1Marscode
Jun 17, 2026
Jul 25, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
This affects all versions of package marscode. There is no path sanitization in the path provided at fs.readFile in index.js.
1Midasolutions
1Eframework
Jun 17, 2026
Jul 24, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Mida eFramework through 2.9.0 allows unauthenticated ../ directory traversal.
1Inneo
1Startup Tools
Jun 17, 2026
Jul 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any furth...Show more
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe web application (served on TCP port 85) includes user input into a filesystem access without any further validation. This might allow an unauthenticated attacker to read files on the server via Directory Traversal, or possibly have unspecified other impact.Show less
1Cauldrondevelopment
1C!
Jun 17, 2026
Jul 23, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
tar/TarFileReader.cpp in Cauldron cbang (aka C-Bang or C!) before 1.6.0 allows Directory Traversal during extraction from a TAR archive.
1Adobe
1Adobe Reader
Jun 17, 2026
Jul 22, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Adobe Reader Mobile versions 20.0.1 and earlier have a directory traversal vulnerability. Successful exploitation could lead to information disclosure.
1Cisco
2Adaptive Security Appliance Software
Firepower Threat Defense
Jun 17, 2026
Jul 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory tra...Show more
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and read sensitive files on a targeted system. The vulnerability is due to a lack of proper input validation of URLs in HTTP requests processed by an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device. The web services file system is enabled when the affected device is configured with either WebVPN or AnyConnect features. This vulnerability cannot be used to obtain access to ASA or FTD system files or underlying operating system (OS) files.Show less
1Intranda
1Goobi Viewer Core
Jun 17, 2026
Jul 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user,...Show more
In Goobi Viewer Core before version 4.8.3, a path traversal vulnerability allows for remote attackers to access files on the server via the application. This is limited to files accessible to the application server user, eg. tomcat, but can potentially lead to the disclosure of sensitive information. The vulnerability has been fixed in version 4.8.3Show less
1Pritunl
1Pritunl Client
Nov 21, 2024
Jul 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.
1Phoenixcontact
1Plcnext Engineer
Jun 17, 2026
Jul 21, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
1Servey Project
1Servey
Jun 17, 2026
Jul 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A path traversal vulnerability in servey version < 3 allows an attacker to read content of any arbitrary file.
1Huawei
4Magic2 Firmware
Mate 20 FirmwareMate 20 Rs Firmware+1 more
Jun 17, 2026
Jul 17, 2020
N/A· v4
2.3 LOW· v3
2.1 LOW· v2
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones...Show more
HUAWEI Mate 20 versions earlier than 10.1.0.160(C00E160R3P8), HUAWEI Mate 20 X versions earlier than 10.1.0.135(C00E135R2P8), HUAWEI Mate 20 RS versions earlier than 10.1.0.160(C786E160R3P8), and Honor Magic2 smartphones versions earlier than 10.1.0.160(C00E160R2P11) have a path traversal vulnerability. The system does not sufficiently validate certain pathname from certain process, successful exploit could allow the attacker write files to a crafted path.Show less
1Rollup Plugin Serve Project
1Rollup Plugin Serve
Jun 17, 2026
Jul 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects all versions of package rollup-plugin-serve. There is no path sanitization in readFile operation.
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Jul 16, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affec...Show more
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct path traversal attacks and obtain read access to sensitive files on an affected system. The vulnerability is due to insufficient validation of HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request that contains directory traversal character sequences to the affected system. A successful exploit could allow the attacker to view arbitrary files on the affected system.Show less
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Jul 16, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on...Show more
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct directory traversal attacks and obtain read and write access to sensitive files on a targeted system. The vulnerability is due to a lack of proper validation of files that are uploaded to an affected device. An attacker could exploit this vulnerability by uploading a crafted file to an affected system. An exploit could allow the attacker to view or modify arbitrary files on the targeted system.Show less
1Socket.io File Project
1Socket.io File
Jun 17, 2026
Jul 15, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options dete...Show more
A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.Show less
1Librehealth
1Librehealth Ehr
Jun 17, 2026
Jul 15, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.