CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Iobroker 1Iobroker.js Controller Jun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adap...Show more |
A path traversal vulnerability in Jenkins Support Core Plugin 2.63 and earlier allows attackers with Overall/Read permission to delete arbitrary files on the Jenkins master. |
iobroker.admin before 3.6.12 allows attacker to include file contents from outside the `/log/file1/` directory. |
permission and access control vulnerability, which exists in V2.1.14 and below versions of C520V21 smart camera devices. An attacker can construct a URL for directory traversal and access to other unauthorized files or r...Show more |
3Canonical DebianRack Cors Project3Debian Linux Rack CorsUbuntu LinuxJun 17, 2026 Nov 14, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in...Show more |
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34. |
1Mcafee 1Advanced Threat Defense Jun 17, 2026 Nov 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Path Traversal: '/absolute/pathname/here' vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attacker to gain unintended access to files on the system via carefully constructed...Show more |
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files. |
1Netgear 2Wnr3500l Firmware Wnr3500u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service. |
1Tp Link 2Tl 1043nd Firmware Tl Wdr4300 FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND.. |
1Asus 2Rt Ac66u Firmware Rt N56u FirmwareNov 21, 2024 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service. |
Systematic IRIS WebForms 5.4 is vulnerable to directory traversal. By manipulating variables that reference files with ../ (and variations), it is possible to list all the directories and check if a particular file exist...Show more |
JEUS 7 Fix#0~5 and JEUS 8Fix#0~1 versions contains a directory traversal vulnerability caused by improper input parameter check when uploading installation file in administration web page. That leads remote attacker to e...Show more |
Portainer before 1.22.1 allows Directory Traversal. |
The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, an...Show more |
1Atlassian 1Jira Service Desk Jun 17, 2026 Nov 7, 2019 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 The Customer Context Filter in Atlassian Jira Service Desk Server and Jira Service Desk Data Center before 3.9.17, from 3.10.0 before 3.16.10, from 4.0.0 before 4.2.6, from 4.3.0 before 4.3.5, from 4.4.0 before 4.4.3, an...Show more |
1Wpmarketplace Project 1Wpmarketplace Nov 21, 2024 Nov 6, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitrary files via a .. (do...Show more |
2Fedoraproject Samba2Fedora SambaJun 17, 2026 Nov 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files...Show more |
The Log module in SECUDOS DOMOS before 5.6 allows local file inclusion. |
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. Path traversal vulnerabilities are caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage these vulnera...Show more |