← Back
CWE-22

9,532 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,532)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Booking Calendar Project
1Booking Calendar
May 13, 2026
Apr 28, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.
1Wbce
1Wbce Cms
May 13, 2026
Apr 28, 2017
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
1Cubecart
1Cubecart
May 13, 2026
Apr 28, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.
1Cubecart
1Cubecart
May 13, 2026
Apr 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
1Cubecart
1Cubecart
May 13, 2026
Apr 28, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.
1Hibara Software
3Attachecase For Java
Attachecase LiteAttachecase Pro
May 13, 2026
Apr 28, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted...Show more
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.Show less
1Hibara
1Attachecase
May 13, 2026
Apr 28, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.
1Simple File Manager Project
1Simple File Manager
May 13, 2026
Apr 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PHP File Manager" component).
1Debian
1Dpkg
May 13, 2026
Apr 26, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attac...Show more
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source package, as demonstrated by use of dpkg-source on NetBSD.Show less
1Modx
1Modx Revolution
May 13, 2026
Apr 25, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
1Mybb
1Mybb
May 13, 2026
Apr 24, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
1Extplorer
1Extplorer
May 13, 2026
Apr 24, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.
1D Link
1Dvg N5402sp Firmware
May 13, 2026
Apr 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.
1Ibm
11Change And Configuration Management Database
Maximo Asset ManagementMaximo Asset Management Essentials+8 more
May 13, 2026
Apr 24, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7....Show more
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.Show less
1Symantec
1Messaging Gateway
May 13, 2026
Apr 14, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servl...Show more
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the sn parameter to brightmail/servlet/com.ve.kavachart.servlet.ChartStream.Show less
1Samsung
1Kies
May 13, 2026
Apr 13, 2017
N/A· v4
6.4 MEDIUM· v3
6.9 MEDIUM· v2
Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.
1Seawell Networks
1Spectrum Sdc
May 13, 2026
Apr 13, 2017
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
1Trendmicro
1Threat Discovery Appliance
May 13, 2026
Apr 12, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass au...Show more
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.Show less
1Intellinet Network
1Nfc 30ir Firmware
May 13, 2026
Apr 11, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
1Intellinet Network
1Nfc 30ir Firmware
May 13, 2026
Apr 11, 2017
N/A· v4
4.9 MEDIUM· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI sc...Show more
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM.1.6.16.05 allows remote attackers to read arbitrary files via a request to a vendor-supplied CGI script that is used to read HTML text file, but that does not do any URI/path sanitization.Show less