CWE-22
9,537 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,537)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Webcalendar Project 1Webcalendar May 13, 2026 Aug 29, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors. |
1Nippon Antenna 1Scr02hd Firmware May 13, 2026 Aug 29, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to read arbitrary files via unspecified vectors. |
Directory traversal vulnerability in the XMLRPC interface in Red Hat Satellite 5. |
Directory traversal vulnerability in ES File Explorer 3.2.4.1. |
Directory traversal vulnerability in unshield 1.0-1. |
Directory traversal vulnerability in ppmd 10.1-5. |
Multiple directory traversal vulnerabilities in ha 0.999p+dfsg-5. |
Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.3 and earlier, and 5.3.0.1 and earlier. |
1Manageengine 4Assetexplorer It360Servicedesk Plus+1 moreMay 13, 2026 Aug 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to execute arbitrary code. |
1Manageengine 4Assetexplorer It360Servicedesk Plus+1 moreMay 13, 2026 Aug 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4. |
1Riverbed 1Opnet App Response Xpert May 13, 2026 Aug 26, 2017 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Directory traversal vulnerability in viewer_script.jsp in Riverbed OPNET App Response Xpert (ARX) version 9.6.1 allows remote authenticated users to inject arbitrary commands to read OS files. |
2Automatedlogic Carrier3Automatedlogic Webctrl I VuSitescan WebMay 13, 2026 Aug 25, 2017 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteSc...Show more |
1Spidercontrol 1Scada Web Server May 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files. |
1Phpmybackuppro 1Phpmybackuppro May 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is u...Show more |
1Phpmybackuppro 1Phpmybackuppro May 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is u...Show more |
3Canonical FedoraprojectGnu3Fedora PatchUbuntu LinuxMay 13, 2026 Aug 25, 2017 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a di...Show more |
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php. |
The MultiPathResource class in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to read arbitrary files via a path traversal vulnerability when Fisheye or Crucible is running on the...Show more |
Directory traversal vulnerability in the SYNO.DNSServer.Zone.MasterZoneConf in Synology DNS Server before 2.2.1-3042 allows remote authenticated attackers to write arbitrary files via the domain_name parameter. |
Directory traversal vulnerability in minion id validation in SaltStack Salt before 2016.11.7 and 2017.7.x before 2017.7.1 allows remote minions with incorrect credentials to authenticate to a master via a crafted minion...Show more |