← Back
CWE-22

9,526 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,526)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Lacie
Seagate
5Goflex Sattelite
Lac9000436u FirmwareLac9000464u Firmware+2 more
May 6, 2026
Dec 31, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to r...Show more
Absolute path traversal vulnerability on Seagate GoFlex Satellite, Seagate Wireless Mobile Storage, Seagate Wireless Plus Mobile Storage, and LaCie FUEL devices with firmware before 3.4.1.105 allows remote attackers to read arbitrary files via a full pathname in a download request during a Wi-Fi session.Show less
1Zte
1Zxhn H108n R1a Firmware
May 6, 2026
Dec 30, 2015
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
1Honeywell
2Midas Black Firmware
Midas Firmware
May 6, 2026
Dec 21, 2015
N/A· v4
8.6 HIGH· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuratio...Show more
Directory traversal vulnerability in the web server on Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allows remote attackers to bypass authentication, and write to a configuration file or trigger a calibration or test, via unspecified vectors.Show less
1Joomla
1Joomla
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknown vectors.
1Joomla
1Joomla
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences in the XML install file in an extension package archive.
1Bitrix
1Mpbuilder
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" arr...Show more
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the element name of the "work" array parameter to admin/bitrix.mpbuilder_step2.php.Show less
1Bitrix
1Xscan
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service...Show more
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users to rename arbitrary files, and consequently obtain sensitive information or cause a denial of service, via a .. (dot dot) in the file parameter to admin/bitrix.xscan_worker.php.Show less
1Cisco
1Emergency Responder
May 6, 2026
Dec 13, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the Tools menu in Cisco Emergency Responder 10.5(1.10000.5) allows remote authenticated users to write to arbitrary files via a crafted filename, aka Bug ID CSCuv21781.
1Apple
1Iphone Os
May 6, 2026
Dec 11, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Mobile Backup in Photos in Apple iOS before 9.2 allows attackers to read arbitrary files via a crafted pathname.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Nov 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequen...Show more
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.Show less
1Huawei
1Ar Firmware
May 6, 2026
Nov 24, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary dire...Show more
Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors.Show less
1Matomo
1Matomo
May 6, 2026
Nov 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.
1Huawei
3Hg532e
Hg532nHg532s
May 6, 2026
Nov 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability on Huawei HG532e, HG532n, and HG532s devices allows remote attackers to read arbitrary files via a .. (dot dot) in an icon/ URI.
1Redhat
1Openshift
May 6, 2026
Nov 6, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it t...Show more
Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.Show less
1Owncloud
1Owncloud Server
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot...Show more
Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.Show less
1Ininet Solutions
1Scada Web Server
May 6, 2026
Oct 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Oct 23, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO a...Show more
Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive.Show less
2Microsoft
Owncloud
3Owncloud
Owncloud ServerWindows
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code v...Show more
Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.Show less
1Avas!t
1Avast! Antivirus
May 6, 2026
Oct 18, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Avast before 150918-0 allows remote attackers to delete or write to arbitrary files via a crafted entry in a ZIP archive.
1Font Project
1Font
May 6, 2026
Oct 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.