← Back
CWE-22

9,537 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,537)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webcalendar Project
1Webcalendar
May 13, 2026
Aug 29, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
1Nippon Antenna
1Scr02hd Firmware
May 13, 2026
Aug 29, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors.
1Redhat
1Satellite
May 13, 2026
Aug 28, 2017
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5.
1Estrongs
1Es File Explorer
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
1Unshield Project
1Unshield
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in unshield 1.0-1.
1Ppmd Project
1Ppmd
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in ppmd 10.1-5.
1Linux Ha
1Ha
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5.
1Sap
1Hybris
May 13, 2026
Aug 28, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier.
1Manageengine
4Assetexplorer
It360Servicedesk Plus+1 more
May 13, 2026
Aug 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code.
1Manageengine
4Assetexplorer
It360Servicedesk Plus+1 more
May 13, 2026
Aug 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
1Riverbed
1Opnet App Response Xpert
May 13, 2026
Aug 26, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to read OS files.
2Automatedlogic
Carrier
3Automatedlogic Webctrl
I VuSitescan Web
May 13, 2026
Aug 25, 2017
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteSc...Show more
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior. An authenticated attacker may be able to overwrite files that are used to execute code. This vulnerability does not affect version 6.5 of the software.Show less
1Spidercontrol
1Scada Web Server
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
1Phpmybackuppro
1Phpmybackuppro
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is u...Show more
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.Show less
1Phpmybackuppro
1Phpmybackuppro
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is u...Show more
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2009-4050.Show less
3Canonical
FedoraprojectGnu
3Fedora
PatchUbuntu Linux
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a di...Show more
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.Show less
1Zen Cart
1Zen Cart
May 13, 2026
Aug 24, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.
1Atlassian
2Crucible
Fisheye
May 13, 2026
Aug 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the...Show more
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the Microsoft Windows operating system.Show less
1Synology
1Dns Server
May 13, 2026
Aug 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter.
1Saltstack
1Salt
May 13, 2026
Aug 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion...Show more
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion ID.Show less