CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Nortekcontrol 2Linear Emerge 5000p Firmware Linear Emerge 50p FirmwareJun 17, 2026 Jul 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Linear eMerge 50P/5000P devices allow Cookie Path Traversal. |
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter. |
Relative path traversal vulnerability in SYNO.PhotoStation.File in Synology Photo Station before 6.8.11-3489 and before 6.3-2977 allows remote attackers to upload arbitrary files via the uploadphoto parameter. |
In WebAccess/SCADA, Versions 8.3.5 and prior, a path traversal vulnerability is caused by a lack of proper validation of a user-supplied path prior to use in file operations. An attacker can leverage this vulnerability t...Show more |
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal. |
1Mcafee 1Enterprise Security Manager Jun 17, 2026 Jun 27, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Directory Traversal vulnerability in McAfee Enterprise Security Manager (ESM) prior to 11.2.0 and prior to 10.4.0 allows authenticated user to gain elevated privileges via specially crafted input. |
1Abb 1Pb610 Panel Builder 600 Firmware Jun 17, 2026 Jun 27, 2019 N/A· v4 7.3 HIGH· v3 4.1 MEDIUM· v2 In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attac...Show more |
1Ibm 7Rational Collaborative Lifecycle Management Rational Doors Next GenerationRational Engineering Lifecycle Manager+4 moreJun 17, 2026 Jun 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IBM Rational Collaborative Lifecycle Management 6.0 through 6.0.6.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequenc...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jun 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jun 27, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to upload arbitrary files on an affected device. The vulnerability is due...Show more |
BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution via the theme cookie to the File Manager. NOTE: this issue exists because of an incomplete fix for CVE-2019-6714. |
1Dotnetblogengine 1Blogengine.net Jun 17, 2026 Jun 21, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 BlogEngine.NET 3.3.7.0 and earlier allows Directory Traversal and Remote Code Execution because file creation is mishandled, related to /api/upload and BlogEngine.NET/AppCode/Api/UploadController.cs. NOTE: this issue exi...Show more |
Pydio Cells before 1.5.0 fails to neutralize '../' elements, allowing an attacker with minimum privilege to Upload files to, and Delete files/folders from, an unprivileged directory, leading to Privilege escalation. |
1Dell 1Avamar Data Migration Enabler Web Interface Jun 17, 2026 Jun 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to th...Show more |
1Sony 8R5c Firmware Wd65 FirmwareWd75 Firmware+5 moreNov 21, 2024 Jun 19, 2019 N/A· v4 8.1 HIGH· v3 4.8 MEDIUM· v2 The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal. |
NGA ResourceLink 20.0.2.1 allows local file inclusion. |
IBM Campaign 9.1.2 and 10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the...Show more |
Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted location (dot-dot-slash notation) to access files or directories that are elsewhere on the sys...Show more |
1Columbiaweather 1Weather Microserver Firmware Nov 21, 2024 Jun 18, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system. |
1Getvera 2Veraedge Firmware Veralite FirmwareNov 21, 2024 Jun 17, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered on Vera VeraEdge 1.7.19 and Veralite 1.7.481 devices. The device provides a script file called "get_file.sh" which allows a user to retrieve any file stored in the "cmh-ext" folder on the device....Show more |