CWE-22
9,542 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,542)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cybelesoft 1Thinfinity Virtualui Jun 17, 2026 Jun 4, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cybele Thinfinity VirtualUI 2.5.17.2 allows ../ path traversal that can be used for data exfiltration. This enables files outside of the web directory to be retrieved if the exact location is known and the user has permi...Show more |
1Zohocorp 1Manageengine Opmanager Jun 17, 2026 Jun 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed. |
An issue was discovered in Navigate CMS through 2.8.7. It allows Directory Traversal because lib/packages/templates/template.class.php mishandles ../ and ..\ substrings. |
PlayTube 1.8 allows disclosure of user details via ajax.php?type=../admin-panel/autoload&page=manage-users directory traversal, aka local file inclusion. |
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A...Show more |
An issue was discovered in Sysax Multi Server 6.90. An attacker can determine the username (under which the web server is running) by triggering an invalid path permission error. This bypasses the fakepath protection mec...Show more |
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warn...Show more |
1Farsite 1Farlinx X25 Gateway Firmware Nov 21, 2024 Jun 1, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 FarLinX X25 Gateway through 2014-09-25 allows directory traversal via the log-handling feature. |
All versions of snyk-broker after 4.72.0 including and before 4.73.1 are vulnerable to Arbitrary File Read. It allows arbitrary file reads to users with access to Snyk's internal network of any files ending in the follow...Show more |
All versions of snyk-broker before 4.72.2 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users who have access to Snyk's internal network by appending the URL with a fragment identifier and a w...Show more |
All versions of snyk-broker before 4.80.0 are vulnerable to Arbitrary File Read. It allows arbitrary file reads for users with access to Snyk's internal network via directory traversal. |
All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API. |
1Trendmicro 1Interscan Web Security Virtual Appliance Jun 17, 2026 May 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations. |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 May 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a...Show more |
1Microsoft 4Windows 10 Windows ServerWindows Server 2016+1 moreJun 17, 2026 May 21, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020...Show more |
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. |
iSpyConnect.com Agent DVR before 2.7.1.0 allows directory traversal. |
In Apache RocketMQ 4.2.0 to 4.6.0, when the automatic topic creation in the broker is turned on by default, an evil topic like “../../../../topic2020” is sent from rocketmq-client to the broker, a topic folder will be cr...Show more |
1Autoswitch Python Virtualenv Project 1Autoswitch Python Virtualenv Jun 17, 2026 May 13, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0 |
1Simplefilelist 1Simple File List Jun 17, 2026 May 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input. |