← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Photo Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
1Qnap
1Photo Station
Jun 17, 2026
Dec 5, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
1Fronius
66Datamanager Box 2.0 Firmware
Eco 25.0 3 S FirmwareEco 27.0 3 S Firmware+63 more
Jun 17, 2026
Dec 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
1Saltosystem
1Proaccess Space
Jun 17, 2026
Dec 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto...Show more
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.Show less
1Saltosystem
1Proaccess Space
Jun 17, 2026
Dec 3, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
SALTO ProAccess SPACE 5.4.3.0 allows Directory Traversal in the Data Export feature.
1Docker
1Docker
Nov 21, 2024
Dec 2, 2019
N/A· v4
8.6 HIGH· v3
8.5 HIGH· v2
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Docke...Show more
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or (2) build in a Dockerfile.Show less
1Cabextract Project
1Cabextract
Nov 21, 2024
Nov 29, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a...Show more
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.Show less
1Alliedtelesis
1At Gs950/8 Firmware
Jun 17, 2026
Nov 29, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an En...Show more
A Directory Traversal in the Web interface of the Allied Telesis AT-GS950/8 until Firmware AT-S107 V.1.1.3 [1.00.047] allows unauthenticated attackers to read arbitrary system files via a GET request. NOTE: This is an End-of-Life product.Show less
1Rconfig
1Rconfig
Jun 17, 2026
Nov 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there wa...Show more
A downloadFile.php download_file path traversal vulnerability in rConfig through 3.9.3 allows attackers to list files in arbitrary folders and potentially download files. NOTE: the discoverer later reported that there was not a "fully working exploit.Show less
1Hitachienergy
1Relion 670 Firmware
Jun 17, 2026
Nov 27, 2019
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
3Canonical
DebianLinux
3Debian Linux
Linux KernelUbuntu Linux
Jun 17, 2026
Nov 27, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Linux kernel CIFS implementation, version 4.9.0 is vulnerable to a relative paths injection in directory entry lists.
1Imagely
1Nextgen Gallery
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
2Debian
Yaws
2Debian Linux
Yaws
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain content of arbitrary local files via specially-crafted URL request.
1Microsoft
1Codeql
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbitrary code of the attacker's choosing may be executed on the user's beh...Show more
If an attacker can get a user to open a specially prepared directory tree as a workspace in Visual Studio Code with the CodeQL extension active, arbitrary code of the attacker's choosing may be executed on the user's behalf. This is fixed in version 1.0.1 of the extension. Users should upgrade to this version using Visual Studio Code Marketplace's upgrade mechanism. After upgrading, the codeQL.cli.executablePath setting can only be set in the per-user settings, and not in the per-workspace settings. More information about VS Code settings can be found here.Show less
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
2Debian
Gnu
2Debian Linux
Patch
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-...Show more
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.Show less
1Nokia
1Impact
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Nokia IMPACT < 18A: allows full path disclosure
1Naver
1Vaccine
Jun 17, 2026
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
nsGreen.dll in Naver Vaccine 2.1.4 allows remote attackers to overwrite arbitary files via directory traversal sequences in a filename within nsz archive.
1Loftek
1Nexus 543 Firmware
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request.
1Lexmark
1Services Monitor Firmware
Jun 17, 2026
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal technique using /../../../ or ..%2F..%2F..%2F to obtain local files on the host operating system.