← Back
CWE-22

9,542 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,542)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cybelesoft
1Thinfinity Virtualui
Jun 17, 2026
Jun 4, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permi...Show more
Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permissions.Show less
1Zohocorp
1Manageengine Opmanager
Jun 17, 2026
Jun 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.
1Naviwebs
1Navigate Cms
Jun 17, 2026
Jun 3, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings.
1Playtube
1Playtube
Jun 17, 2026
Jun 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion.
1Vmware
1Spring Cloud Config
Jun 17, 2026
Jun 2, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A...Show more
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.Show less
1Sysax
1Multi Server
Jun 17, 2026
Jun 2, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mec...Show more
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mechanism.Show less
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warn...Show more
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages.Show less
1Farsite
1Farlinx X25 Gateway Firmware
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature.
1Synk
1Broker
Jun 17, 2026
May 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the follow...Show more
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the following extensions: yaml, yml or json.Show less
1Synk
1Broker
Jun 17, 2026
May 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a w...Show more
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a whitelisted path e.g. `#package.json`Show less
1Synk
1Broker
Jun 17, 2026
May 29, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal.
1Synk
1Broker
Jun 17, 2026
May 29, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.
1Trendmicro
1Interscan Web Security Virtual Appliance
Jun 17, 2026
May 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.
2Canonical
Mozilla
4Firefox
Firefox EsrThunderbird+1 more
Jun 17, 2026
May 26, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a...Show more
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.Show less
1Microsoft
4Windows 10
Windows ServerWindows Server 2016+1 more
Jun 17, 2026
May 21, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020...Show more
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1021, CVE-2020-1088.Show less
1Druva
1Insync Client
Jun 17, 2026
May 21, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges.
1Ispyconnect
1Agent Dvr
Jun 17, 2026
May 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal.
1Apache
1Rocketmq
Jun 17, 2026
May 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be cr...Show more
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be created in the parent directory in brokers, which leads to a directory traversal vulnerability. Users of the affected versions should apply one of the following: Upgrade to Apache RocketMQ 4.6.1 or later.Show less
1Autoswitch Python Virtualenv Project
1Autoswitch Python Virtualenv
Jun 17, 2026
May 13, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0
1Simplefilelist
1Simple File List
Jun 17, 2026
May 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.