← Back
CWE-22

9,515 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

JSON object

Loading...

CVEs (9,515)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cgene
1Security File Manager
Apr 29, 2026
Jan 12, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in the CGENE Security File Manager Pro application 1.0.6 and earlier, and Security File Manager Trial application 1.0.6 and earlier, for Android allows attackers to overwrite or create a...Show more
Directory traversal vulnerability in the CGENE Security File Manager Pro application 1.0.6 and earlier, and Security File Manager Trial application 1.0.6 and earlier, for Android allows attackers to overwrite or create arbitrary files via unspecified vectors.Show less
1Yuichiro Okuyama
2Tetra Filer
Tetra Filer Free
Apr 29, 2026
Jan 12, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in the tetra filer application 2.3.1 and earlier for Android 4.0.3, tetra filer free application 2.3.1 and earlier for Android 4.0.3, tetra filer application 1.5.1 and earlier for Androi...Show more
Directory traversal vulnerability in the tetra filer application 2.3.1 and earlier for Android 4.0.3, tetra filer free application 2.3.1 and earlier for Android 4.0.3, tetra filer application 1.5.1 and earlier for Android before 4.0.3, and tetra filer free application 1.5.1 and earlier for Android before 4.0.3 allows attackers to overwrite or create arbitrary files via unspecified vectors.Show less
1Aokitaka
2Zip With Pass
Zip With Pass Pro
Apr 29, 2026
Jan 12, 2014
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Directory traversal vulnerability in the aokitaka ZIP with Pass application 4.5.7 and earlier, and ZIP with Pass Pro application 6.3.8 and earlier, for Android allows attackers to overwrite or create arbitrary files via...Show more
Directory traversal vulnerability in the aokitaka ZIP with Pass application 4.5.7 and earlier, and ZIP with Pass Pro application 6.3.8 and earlier, for Android allows attackers to overwrite or create arbitrary files via unspecified vectors.Show less
1Symantec
1Endpoint Protection
Apr 29, 2026
Jan 10, 2014
N/A· v4
N/A· v3
7.2 HIGH· v2
Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows...Show more
Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory.Show less
1Horizon Quick Content Management System Project
1Horizon Quick Content Management System
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in lib/functions/d-load.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.
1Qnap
1Qts
Apr 29, 2026
Jan 9, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
Absolute path traversal vulnerability in cgi-bin/jc.cgi in QNAP QTS before 4.1.0 allows remote attackers to read arbitrary files via a full pathname in the f parameter.
17mediaws
1Edutrac
Apr 29, 2026
Jan 8, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the showmask parameter to installer/overview.php.
2Westerndeal
Wordpress
2Advanced Dewplayer
Wordpress
Apr 29, 2026
Jan 3, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.
1Synology
1Diskstation Manager
Apr 29, 2026
Dec 31, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot do...Show more
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.Show less
1Hot
2Hotbox Router
Hotbox Router Firmware
Apr 29, 2026
Dec 30, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.
1Cisco
1Nx Os
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, C...Show more
Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.Show less
1Cisco
1Nx Os
Apr 29, 2026
Dec 21, 2013
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Directory traversal vulnerability in tar in Cisco NX-OS allows local users to access arbitrary files via crafted command-line arguments, aka Bug IDs CSCty07157, CSCty07159, CSCty07162, and CSCty07164.
1Iscripts
1Autohoster
Apr 29, 2026
Dec 20, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid parameter to websitebuilder/showtemplateimage.php, (2) fname parameter t...Show more
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid parameter to websitebuilder/showtemplateimage.php, (2) fname parameter to admin/downloadfile.php, or (3) id parameter to support/admin/csvdownload.php; or (4) have an unspecified impact via unspecified vectors in support/parser/main_smtp.php.Show less
1Ibm
2Rational Software Architect Design Manager
Rhapsody Design Manager
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temp...Show more
Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.Show less
1Ibm
2Rational Software Architect Design Manager
Rhapsody Design Manager
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
2.1 LOW· v2
Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temp...Show more
Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.Show less
1Rockmongo
1Rockmongo
Apr 29, 2026
Dec 14, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
1Synacor
1Zimbra Collaboration Suite
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin...Show more
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.Show less
1Apache
1Solr
Apr 29, 2026
Dec 7, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response...Show more
Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.Show less
1Easytimestudio
1Easy File Manager
Apr 29, 2026
Dec 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Easytime Studio Easy File Manager 1.1 for iOS allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) to the default URI.
1Tattyan
1Tattyan Hptown
Apr 29, 2026
Dec 5, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in Tattyan HP TOWN before 5_10_1 allows remote attackers to read arbitrary files via a .. (dot dot) in a request.