CWE-22
9,542 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,542)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Horde2Debian Linux GroupwareJun 17, 2026 Mar 23, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exist...Show more |
1Schneider Electric 1Interactive Graphical Scada System Jun 17, 2026 Mar 23, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from...Show more |
Local File Inclusion in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to traverse paths via a plugin test. |
1Netsas 1Enigma Network Management Solution Jun 17, 2026 Mar 19, 2020 N/A· v4 9.6 CRITICAL· v3 5.5 MEDIUM· v2 NETSAS Enigma NMS 65.0.0 and prior suffers from a directory traversal vulnerability that can allow an authenticated user to access files and directories stored outside of the web root folder. By exploiting this vulnerabi...Show more |
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. |
Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx. |
1Trendmicro 1Worry Free Business Security Jun 17, 2026 Mar 18, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication. |
The Hustle (aka wordpress-popup) plugin through 6.0.5 for WordPress allows Directory Traversal to obtain a directory listing via the views/admin/dashboard/ URI. |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 4.6 MEDIUM· v3 3.6 LOW· v2 A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x...Show more |
1Iptanus 1Wordpress File Upload Jun 17, 2026 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib...Show more |
1Kyocera 1Ecosys M5526cdw Firmware Jun 17, 2026 Mar 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The web application of some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was vulnerable to path traversal, allowing an unauthenticated user to retrieve arbitrary files, or check if files or folders exi...Show more |
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read. |
1Safescan 7Ta 8010 Firmware Ta 8015 FirmwareTa 8020 Firmware+4 moreJun 17, 2026 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory Traversal in Safescan Timemoto and TA-8000 series version 1.0 allows unauthenticated remote attackers to execute code via the administrative API. |
Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117 and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege or...Show more |
Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the we...Show more |
Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (../) via the GET parameter crdir, when t...Show more |
Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (f...Show more |
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file. |
SAP NetWeaver UDDI Server (Services Registry), versions- 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50; allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing...Show more |
1Siemens 2Sinvr 3 Central Control Server Sinvr 3 Video ServerJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could a...Show more |