← Back
CWE-22

9,517 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,517)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Mozilla
Oracle
2Firefoxos
Solaris
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted applicatio...Show more
Directory traversal vulnerability in the DeviceStorage API in Mozilla FirefoxOS before 1.2.2 allows attackers to bypass the media sandbox protection mechanism, and read or modify arbitrary files, via a crafted application that uses a relative pathname for a DeviceStorageFile object.Show less
2Mozilla
Oracle
2Firefox
Solaris
May 6, 2026
Mar 19, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (applic...Show more
Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.Show less
2Intel
Mcafee
3Cloud Identity Manager
Cloud Single Sign OnExpressway Cloud Access 360
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated...Show more
Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.Show less
1Mcafee
1Web Gateway
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web f...Show more
Directory traversal vulnerability in McAfee Web Gateway (MWG) 7.4.x before 7.4.1, 7.3.x before 7.3.2.6, and 7.2.0.9 and earlier allows remote authenticated users to read arbitrary files via a crafted request to the web filtering port.Show less
1Sophos
2Web Appliance
Web Appliance Firmware
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
1Aspen
1Aspen
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI.
2Apache
Mochiweb Project
2Couchdb
Mochiweb
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to r...Show more
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1.1.x before 1.1.2, and 1.2.x before 1.2.1, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the default URI.Show less
1R Company
1Unzipper
May 6, 2026
Mar 18, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in the R-Company Unzipper application 1.0.1 and earlier for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.
1Google
1Chrome
May 6, 2026
Mar 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors.
1Google
1Chrome Os
May 6, 2026
Mar 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in CrosDisks in Google Chrome OS before 33.0.1750.152 has unspecified impact and attack vectors.
1Owncloud
1Owncloud
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in apps/files_trashbin/index.php in ownCloud Server before 5.0.6 allows remote authenticated users to access arbitrary files via a .. (dot dot) in the dir parameter.
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Directory traversal vulnerability in lib/files/view.php in ownCloud before 4.0.15, 4.5.x 4.5.11, and 5.x before 5.0.6 allows remote authenticated users to access arbitrary files via unspecified vectors.
5Contec
DebianLighttpd+2 more
6Debian Linux
LighttpdLinux Enterprise High Availability Extension+3 more
May 6, 2026
Mar 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_che...Show more
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.Show less
1Raoul Proenca
1Gnew
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the gnew_language cookie.
1Schneems
1Wicked
May 6, 2026
Mar 11, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
1Atlassian
1Jira
May 6, 2026
Mar 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.
1Atlassian
1Jira
May 6, 2026
Mar 9, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in the Importers plugin in Atlassian JIRA before 6.0.5 allows remote attackers to create arbitrary files via unspecified vectors.
1Videowhisper
2Live Streaming Integration Plugin
Videowhisper Live Streaming Integration
May 6, 2026
Mar 6, 2014
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to l...Show more
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for WordPress allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_login.php or (2) delete arbitrary files via a .. (dot dot) in the s parameter to ls/rtmp_logout.php.Show less
1Ibm
1Tealeaf Cx
May 6, 2026
Mar 6, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypas...Show more
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.Show less
1Ibm
2Algo One
Algo Risk Application
May 6, 2026
Mar 6, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) c...Show more
Multiple directory traversal vulnerabilities in Algo Risk Application (ARA) 2.4.0.1 through 4.9.1 in IBM Algo One allow remote authenticated users to bypass intended access restrictions via a crafted pathname for a (1) configuration or (2) JAR file.Show less