CWE-22
9,540 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,540)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Syntastic Project2Debian Linux SyntasticNov 21, 2024 May 20, 2018 N/A· v4 7.5 HIGH· v3 8.5 HIGH· v2 Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrar...Show more |
util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal. |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 May 17, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a path traversal attack on a targeted system. The vulnerabi...Show more |
1Advantech 4Webaccess Webaccess/nmsWebaccess Dashboard+1 moreJun 17, 2026 May 15, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and pri...Show more |
1Advantech 4Webaccess Webaccess/nmsWebaccess Dashboard+1 moreJun 17, 2026 May 15, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and pri...Show more |
1Advantech 4Webaccess Webaccess/nmsWebaccess Dashboard+1 moreNov 21, 2024 May 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and pri...Show more |
1Vmware 1Spring Integration Zip Nov 21, 2024 May 15, 2018 N/A· v4 4.7 MEDIUM· v3 4.0 MEDIUM· v2 Addresses partial fix in CVE-2018-1261. Pivotal spring-integration-zip, versions prior to 1.0.2, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other ar...Show more |
1Ultimatemember 1User Profile & Membership Nov 21, 2024 May 14, 2018 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors. |
1Ultimatemember 1User Profile & Membership Nov 21, 2024 May 14, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecified vectors. |
1Vmware 1Spring Integration Zip Nov 21, 2024 May 11, 2018 N/A· v4 4.7 MEDIUM· v3 4.0 MEDIUM· v2 Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) th...Show more |
1Huawei 2Hirouter Cd20 Firmware Ws5200 FirmwareJun 17, 2026 May 10, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions before WS5200-10 1.9.6 have a path traversal vulnerability. Due to the lack of validation while these...Show more |
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php pa...Show more |
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undis...Show more |
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that allows attackers able to configure the HTML Publisher build step to override arbitrary files on the J...Show more |
1Medtronic 12090 Carelink Programmer Firmware Jun 17, 2026 May 4, 2018 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system. |
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request which provides read-only access to any file on the filesystem of the host t...Show more |
1Cisco 2Prime Data Center Network Manager Prime InfrastructureNov 21, 2024 May 2, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute th...Show more |
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation. |
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings. |
1Seagate 1Personal Cloud Firmware Nov 21, 2024 Apr 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url. |