← Back
CWE-22

9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,540)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Jenkins
Nov 21, 2024
Jan 23, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler...Show more
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jelly/src/main/java/org/kohsuke/stapler/jelly/JellyFacet.java, jruby/src/main/java/org/kohsuke/stapler/jelly/jruby/JRubyFacet.java, jsp/src/main/java/org/kohsuke/stapler/jsp/JSPFacet.java that allows attackers to render routable objects using any view in Jenkins, exposing internal information about those objects not intended to be viewed, such as their toString() representation.Show less
1Axway
1File Tranfer Direct
Jun 17, 2026
Jan 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial...Show more
In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' characters, as demonstrated by an initial /h2hdocumentation//%2e%2e/ substring.Show less
1Rsa
1Authentication Manager
Nov 21, 2024
Jan 16, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license t...Show more
The Quick Setup component of RSA Authentication Manager versions prior to 8.4 is vulnerable to a relative path traversal vulnerability. A local attacker could potentially provide an administrator with a crafted license that if used during the quick setup deployment of the initial RSA Authentication Manager system, could allow the attacker unauthorized access to that system.Show less
1Mailenable
1Mailenable
Nov 21, 2024
Jan 16, 2019
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
1Woocommerce
1Woocommerce
Nov 21, 2024
Jan 15, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not bein...Show more
The logging system of the Automattic WooCommerce plugin before 3.4.6 for WordPress is vulnerable to a File Deletion vulnerability. This allows deletion of woocommerce.php, which leads to certain privilege checks not being in place, and therefore a shop manager can escalate privileges to admin.Show less
1Shopxo
1Shopxo
Jun 17, 2026
Jan 10, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input mishandling by the rmdir method. Attackers can delete arbitrary files by...Show more
An issue was discovered in ShopXO 1.2.0. In the UnlinkDir method of the FileUtil.php file, the input parameters are not checked, resulting in input mishandling by the rmdir method. Attackers can delete arbitrary files by using "../" directory traversal.Show less
1Ionicframework
1Ionic Web View
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspec...Show more
Directory traversal vulnerability in cordova-plugin-ionic-webview versions prior to 2.2.0 (not including 2.0.0-beta.0, 2.0.0-beta.1, 2.0.0-beta.2, and 2.1.0-0) allows remote attackers to access arbitrary files via unspecified vectors.Show less
1Cybozu
1Remote Service Manager
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.
1Cybozu
1Remote Service Manager
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.
1Jenkins
1Jenkins
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file...Show more
A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.Show less
1Cybozu
1Dezie
Nov 21, 2024
Jan 9, 2019
N/A· v4
9.1 CRITICAL· v3
7.5 HIGH· v2
Directory traversal vulnerability in Cybozu Dezie 8.0.2 to 8.1.2 allows remote attackers to read arbitrary files via HTTP requests.
1Cybozu
1Office
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via Keitai Screen.
1Cybozu
1Office
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.
1Cybozu
1Mailwise
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.
1Arc Project
1Arc
Nov 21, 2024
Jan 7, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ARC 5.21q allows directory traversal via a full pathname in an archive file.
1Openrefine
1Openrefine
Jun 17, 2026
Jan 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.
1Expressvpn
1Expressvpn
Nov 21, 2024
Jan 2, 2019
N/A· v4
7.1 HIGH· v3
6.6 MEDIUM· v2
An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side...Show more
An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RPC protocol over HTTP is used for communication. The JSON-RPC XVPN.GetPreference and XVPN.SetPreference methods are vulnerable to path traversal, and allow reading and writing files on the file system on behalf of the service.Show less
1Hp
1Ucmdb Configuration Manager
Nov 21, 2024
Dec 31, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10....Show more
Remote Directory Traversal and Remote Disclosure of Privileged Information in UCMDB Configuration Management Service, version 10.22, 10.22 CUP1, 10.22 CUP2, 10.22 CUP3, 10.22 CUP4, 10.22 CUP5, 10.22 CUP6, 10.22 CUP7, 10.33, 10.33 CUP1, 10.33 CUP2, 10.33 CUP3, 2018.02, 2018.05, 2018.08, 2018.11. The vulnerabilities could allow Remote Directory Traversal and Remote Disclosure of Privileged InformationShow less
1Txjia
1Imcat
Nov 21, 2024
Dec 30, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
imcat 4.4 allows directory traversal via the root/run/adm.php efile parameter.
1Lfdycms
1Lei Feng Tv Cms
Nov 21, 2024
Dec 30, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin.php?s=/Template/edit/path/*web*..*..*..*..*1.txt.html URI to read the 1.txt fil...Show more
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin.php?s=/Template/edit/path/*web*..*..*..*..*1.txt.html URI to read the 1.txt file.Show less