CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in OpenEMR before 5.0.1 Patch 7. Directory Traversal exists via docid=../ to /portal/lib/download_template.php. |
1Zohocorp 1Manageengine Netflow Analyzer Jun 17, 2026 May 17, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerability in the Administration zone, in /netflow/servlet/CReportPDFServlet (via the parameter schFilePat...Show more |
MacDown 0.7.1 allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. |
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substring in a shared note. |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 May 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files w...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 May 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files w...Show more |
1Cisco 2Evolved Programmable Network Manager Prime InfrastructureJun 17, 2026 May 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager software could allow an authenticated, remote attacker to download and view files w...Show more |
1Cisco 1Video Surveillance Manager Jun 17, 2026 May 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Video Surveillance Manager could allow an unauthenticated, remote attacker to access sensitive information. The vulnerability is due to improper validation o...Show more |
2Microsoft Rapidflows2.net Framework Rapid4Jun 17, 2026 May 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 GetFile.aspx in Rapid4 RapidFlows Enterprise Application Builder 4.5M.23 (when used with .NET Framework 4.5) allows Local File Inclusion via the FileDesc parameter. |
1Microstrategy 1Web Services Jun 17, 2026 May 14, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 An issue was discovered in MicroStrategy Web Services (the Microsoft Office plugin) before 10.4 Hotfix 7, and before 10.11. The vulnerability is unauthenticated and leads to access to the asset files with the MicroStrate...Show more |
1Gracemedia Media Player Project 1Gracemedia Media Player Jun 17, 2026 May 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter. |
1Bosch 4Divar Ip 2000 Firmware Divar Ip 5000 FirmwareVideo Management System+1 moreJun 17, 2026 May 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files on the system via the...Show more |
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated a...Show more |
1Cam 1The University Of Cambridge Web Authentication System Apache Authentication Agent Nov 21, 2024 May 13, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The...Show more |
1Page Flip Book Project 1Page Flip Book Nov 21, 2024 May 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Directory traversal vulnerability in pageflipbook.php script from index.php in Page Flip Book plugin for WordPress (wppageflip) allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in t...Show more |
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path. |
Path traversal using symlink in npm harp module versions <= 0.29.0. |
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Optio...Show more |
1Dkpro Core Project 1Dkpro Core Jun 17, 2026 May 10, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 core/api/datasets/internal/actions/Explode.java in the Dataset API in DKPro Core through 1.10.0 allows Directory Traversal, resulting in the overwrite of local files with the contents of an archive. |
Apache Karaf Config service provides a install method (via service or MBean) that could be used to travel in any directory and overwrite existing file. The vulnerability is low if the Karaf process user has limited permi...Show more |