CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Local File Inclusion vulnerability in the Nevma Adaptive Images plugin before 0.6.67 for WordPress allows remote attackers to retrieve arbitrary files via the $REQUEST['adaptive-images-settings']['source_file'] paramet...Show more |
zzcms zzmcms 8.3 and earlier is affected by: File Delete to getshell. The impact is: getshell. The component is: /user/ppsave.php. |
1Fanucamerica 1Robotics Virtual Robot Controller Jun 17, 2026 Jul 17, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The remote admin webserver on FANUC Robotics Virtual Robot Controller 8.23 allows Directory Traversal via a forged HTTP request. |
A path traversal vulnerability in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java allowed attackers with Job/Configure permission to define a file parameter w...Show more |
IBM Maximo Asset Management 7.6 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on...Show more |
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive) via an archive with an executable file that has an initial ../ in its filename. This allows attacke...Show more |
1Citrix 2Netscaler Sd Wan Sd WanJun 17, 2026 Jul 16, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow Directory Traversal. |
1Microsoft 10Remote Desktop Client Windows 10Windows 11 21h2+7 moreJun 17, 2026 Jul 15, 2019 N/A· v4 8.0 HIGH· v3 8.5 HIGH· v2 A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execut...Show more |
1Http File Server Project 1Http File Server Jun 17, 2026 Jul 15, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders. |
ZTE MW NR8000V2.4.4.03 and NR8000V2.4.4.04 are impacted by path traversal vulnerability. Due to path traversal,users can download any files. |
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1. |
1Serve Here.js Project 1Serve Here.js Jun 17, 2026 Jul 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder. |
There is a path traversal vulnerability on Huawei Share. The software does not properly validate the path, an attacker could crafted a file path when transporting file through Huawei Share, successful exploit could allow...Show more |
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an index.php?q=system-handle-form-submit POST request because of an include_once in system_handle_form_su...Show more |
MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or potentially read files in arbitrary folders accessible by the IIS user. This...Show more |
2Canonical Flightcrew Project2Flightcrew Ubuntu LinuxJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 FlightCrew v0.9.2 and older are vulnerable to a directory traversal, allowing attackers to write arbitrary files via a ../ (dot dot slash) in a ZIP archive entry that is mishandled during extraction. |
1Dotnetblogengine 1Blogengine.net Jun 17, 2026 Jul 3, 2019 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 BlogEngine.NET 3.3.7.0 allows /api/filemanager Directory Traversal via the path parameter. |
A path traversal flaw was found in spacewalk-proxy, all versions through 2.9, in the way the proxy processes cached client tokens. A remote, unauthenticated attacker could use this flaw to test the existence of arbitrary...Show more |
1Nortekcontrol 2Linear Emerge Elite Firmware Linear Emerge Essential FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Linear eMerge E3-Series devices allow File Inclusion. |
1Nortekcontrol 2Linear Emerge Elite Firmware Linear Emerge Essential FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Linear eMerge E3-Series devices allow Directory Traversal. |