CWE-22
9,526 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,526)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Arubanetworks 1Clearpass Policy Manager May 6, 2026 May 28, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 Directory traversal vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote administrators to execute arbitrary files via unspecified vectors. |
Directory traversal vulnerability in IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to write to arbitrary files via unspecified vector...Show more |
1Thecartpress 1Thecartpress Ecommerce Shopping Cart May 6, 2026 May 14, 2015 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via...Show more |
Directory traversal vulnerability in Elasticsearch before 1.4.5 and 1.5.x before 1.5.2, when a site plugin is enabled, allows remote attackers to read arbitrary files via unspecified vectors. |
Multiple directory traversal vulnerabilities in Magento Community Edition (CE) 1.9.1.0 and Enterprise Edition (EE) 1.14.1.0 allow remote authenticated users to include and execute certain PHP files via (1) .. (dot dot) s...Show more |
2Canonical Ubuntu2Network Manager Ubuntu LinuxMay 6, 2026 Apr 29, 2015 N/A· v4 N/A· v3 4.6 MEDIUM· v2 Directory traversal vulnerability in the Ubuntu network-manager package for Ubuntu (vivid) before 0.9.10.0-4ubuntu15.1, Ubuntu 14.10 before 0.9.8.8-0ubuntu28.1, and Ubuntu 14.04 LTS before 0.9.8.8-0ubuntu7.1 allows local...Show more |
Directory traversal vulnerability in TAGAWA Takao TransmitMail 1.0.11 through 1.5.8 allows remote attackers to read arbitrary files via vectors related to attachment handling. |
1Tp Link 25Archer C5 (1.2) Firmware Archer C5 FirmwareArcher C7 (2.0) Firmware+22 moreApr 21, 2026 Apr 22, 2015 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0...Show more |
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (...Show more |
Directory traversal vulnerability in Lhaplus before 1.70 allows remote attackers to write to arbitrary files via a crafted archive. |
Directory traversal vulnerability in inc/autoload.function.php in GLPI before 0.84.8 allows remote attackers to include and execute arbitrary local files via a .._ (dot dot underscore) in an item type to the getItemForIt...Show more |
4Canonical DebianGnu+1 more4Debian Linux Enterprise LinuxMailman+1 moreMay 6, 2026 Apr 13, 2015 N/A· v4 N/A· v3 7.6 HIGH· v2 Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name. |
Directory traversal vulnerability in Backup in Apple iOS before 8.3 allows attackers to read arbitrary files via a crafted relative path. |
2Arj Software Fedoraproject2Arj Archiver FedoraMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in...Show more |
1Ericsson 1Drutt Mobile Service Delivery Platform May 6, 2026 Apr 6, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5, and 6 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the d...Show more |
1Cisco 1Prime Data Center Network Manager Apr 22, 2026 Apr 3, 2015 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241. |
1Honeywell 8Excel Web Xl 1000c1000 600 I/o Excel Web Xl 1000c1000 600 I/o UuklExcel Web Xl 1000c100 104 I/o+5 moreMay 6, 2026 Mar 31, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O, XL1000C100 104 I/O, XL1000C500 300 I/O, XL1000C1000 600 I/O, XL1000C50U 52 I/O UUKL, XL1000C100U 104 I/O UUKL, XL1000C500U 300...Show more |
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to index.ph...Show more |
1Cisco 1Anyconnect Secure Mobility Client May 6, 2026 Mar 17, 2015 N/A· v4 N/A· v3 6.6 MEDIUM· v2 The Hostscan module in Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to write to arbitrary files via crafted IPC messages, aka Bug ID CSCus79173. |
3Canonical LibarchiveOpensuse3Libarchive OpensuseUbuntu LinuxMay 6, 2026 Mar 15, 2015 N/A· v4 N/A· v3 6.4 MEDIUM· v2 Absolute path traversal vulnerability in bsdcpio in libarchive 3.1.2 and earlier allows remote attackers to write to arbitrary files via a full pathname in an archive. |