← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eq 3
2Ccu2 Firmware
Cux Daemon
Jun 17, 2026
Oct 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A Local File Inclusion (LFI) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to read sensitive files via a simple HTTP Request.
1Cisco
1Wireless Lan Controller Software
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization o...Show more
A vulnerability in the CLI of Cisco Wireless LAN Controller (WLC) Software could allow an authenticated, local attacker to view system files that should be restricted. This vulnerability is due to improper sanitization of user-supplied input in command-line parameters that describe filenames. An attacker could exploit this vulnerability by using directory traversal techniques to submit a path to a desired file location. A successful exploit could allow the attacker to view system files that may contain sensitive information.Show less
1Cisco
2Spa112 Firmware
Spa122 Firmware
Jun 17, 2026
Oct 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. T...Show more
A vulnerability in the web-based management interface of Cisco SPA100 Series Analog Telephone Adapters (ATAs) could allow an authenticated, remote attacker to view the contents of arbitrary files on an affected device. The vulnerability is due to improper input validation in the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to retrieve the contents of arbitrary files on the device, possibly resulting in the disclosure of sensitive information.Show less
1Cybelsoft
1Thinvnc
Jun 17, 2026
Oct 16, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for...Show more
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.Show less
1Nazgul
1Nostromo Nhttpd
Jun 17, 2026
Oct 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
1Nazgul
1Nostromo Nhttpd
Jun 17, 2026
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
1Jnoj
1Jiangnan Online Judge
Jun 17, 2026
Oct 13, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file reading via the web/polygon/problem/viewfile?id=1&name=../ substring.
1Jnoj
1Jiangnan Online Judge
Jun 17, 2026
Oct 13, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Jiangnan Online Judge (aka jnoj) 0.8.0 has Directory Traversal for file deletion via the web/polygon/problem/deletefile?id=1&name=../ substring.
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/...Show more
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.Show less
1Icewarp
1Webclient
Nov 21, 2024
Oct 11, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/inde...Show more
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where IceWarp is installed (or the whole system) and read arbitrary files.Show less
1Robot Cpa
1Robotcpa
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
1Estrutura Basica Project
1Estrutura Basica
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
1Ionadas
1History Collection
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
1S3bubble
1S3bubble Amazon S3 Audio Streaming
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
1S3bubble
1S3bubble Amazon S3 Html 5 Video With Adverts
Nov 21, 2024
Oct 10, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
1Koji Project
1Koji
Jun 17, 2026
Oct 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Koji through 1.18.0 allows remote Directory Traversal, with resultant Privilege Escalation.
1Juniper
1Junos
Jun 17, 2026
Oct 9, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with Next-Generation Routing Engine (NG-RE) allows a local authenticated user to read sensitive system fi...Show more
A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with Next-Generation Routing Engine (NG-RE) allows a local authenticated user to read sensitive system files. This issue only affects NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series with Next-Generation Routing Engine (NG-RE) which uses vmhost. This issue affects Juniper Networks Junos OS on NFX150 Series and QFX10K, EX9200 Series, MX Series and PTX Series with NG-RE and vmhost: 15.1F versions prior to 15.1F6-S12 16.1 versions starting from 16.1R6 and later releases, including the Service Releases, prior to 16.1R6-S6, 16.1R7-S3; 17.1 versions prior to 17.1R3; 17.2 versions starting from 17.2R1-S3, 17.2R3 and later releases, including the Service Releases, prior to 17.2R3-S1; 17.3 versions starting from 17.3R1-S1, 17.3R2 and later releases, including the Service Releases, prior to 17.3R3-S3; 17.4 versions starting from 17.4R1 and later releases, including the Service Releases, prior to 17.4R1-S6, 17.4R2-S2, 17.4R3; 18.1 versions prior to 18.1R2-S4, 18.1R3-S3; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S2, 18.3R2; 18.4 versions prior to 18.4R1-S1, 18.4R2. This issue does not affect: Juniper Networks Junos OS 15.1 and 16.2.Show less
1Joomlashack
1Shack Forms Pro
Jun 17, 2026
Oct 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The Shack Forms Pro extension before 4.0.32 for Joomla! allows path traversal via a file attachment.
1Fiberhome
1Hg2201t Firmware
Jun 17, 2026
Oct 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
/var/WEB-GUI/cgi-bin/downloadfile.cgi on FiberHome HG2201T 1.00.M5007_JS_201804 devices allows pre-authentication Directory Traversal for reading arbitrary files.
1Yeahlink
3T49g Firmware
T58v FirmwareVp59 Firmware
Jun 17, 2026
Oct 8, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement...Show more
Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password replacement and arbitrary code execution as root.Show less