CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Androvideo Geovision3Gv Vd8700 Firmware Gv Vr360 FirmwareVd 1 FirmwareJun 17, 2026 Aug 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication. |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Aug 29, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubec...Show more |
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubec...Show more |
cli/lib/main.js in Entropic before 2019-06-13 does not reject / and \ in command names, which might allow a directory traversal attack in unusual situations. |
1Elearningfreak 1Insert Or Embed Articulate Content Jun 17, 2026 Aug 27, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 The insert-or-embed-articulate-content-into-wordpress plugin before 4.29991 for WordPress has insufficient restrictions on deleting or renaming by a Subscriber. |
1Alkacon 1Opencms Apollo Template Jun 17, 2026 Aug 27, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an attacker to access server resources: clearhistory.jsp, convertxml.jsp, group_new.jsp, loginmessage.jsp,...Show more |
MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storag...Show more |
1Microfocus 1Verastream Host Integrator Jun 17, 2026 Aug 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Path traversal vulnerability in Micro Focus Verastream Host Integrator (VHI), versions 7.7 SP2 and earlier, The vulnerability allows remote unauthenticated attackers to read arbitrary files. |
comelz Quark before 2019-03-26 allows directory traversal to locations outside of the project directory. |
1Power Response Project 1Power Response Jun 17, 2026 Aug 23, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Power-Response before 2019-02-02 allows directory traversal (up to the application's main directory) via a plugin. |
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler. |
jc21 Nginx Proxy Manager before 2.0.13 allows %2e%2e%2f directory traversal. |
Cuberite before 2019-06-11 allows webadmin directory traversal via ....// because the protection mechanism simply removes one ../ substring. |
1Codection 1Import Users From Csv With Meta Jun 17, 2026 Aug 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The import-users-from-csv-with-meta plugin before 1.14.2.1 for WordPress has directory traversal. |
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal. |
1Insert Pages Project 1Insert Pages Nov 21, 2024 Aug 22, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths. |
1Wpsupportplus 1Wp Support Plus Responsive Ticket System Nov 21, 2024 Aug 22, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. |
NLTK Downloader before 3.4.5 is vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in an NLTK package (ZIP archive) that is mishandled during extraction. |
Mirasys VMS before V7.6.1 and 8.x before V8.3.2 mishandles the Download() method of AutoUpdateService in SMServer.exe, leading to Directory Traversal. An attacker could use ..\ with this method to iterate over lists of i...Show more |
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow an attacker to traverse the file system to access files or directories that are outside of the rest...Show more |