CWE-23
490 CVEs • Abstraction: Base
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CVEs (490)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerab...Show more |
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the...Show more |
1Softing 6Edgeaggregator EdgeconnectorOpc+3 moreJun 17, 2026 Aug 17, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and...Show more |
1Ovarro 8Tbox Lt2 530 Firmware Tbox Lt2 532 FirmwareTbox Lt2 540 Firmware+5 moreJun 17, 2026 Jul 28, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution. |
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The i...Show more |
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary code. |
2Debian Tzinfo Project2Debian Linux TzinfoJun 17, 2026 Jul 22, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as well as those prior to 1.2.10 when used with the Ruby data source tzinf...Show more |
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based managemen...Show more |
1Cisco 1Unified Communications Manager Jun 17, 2026 Jul 6, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated...Show more |
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files. |
1Dell 1Wyse Management Suite Jun 17, 2026 Jun 24, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesyste...Show more |
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow...Show more |
1Keysight 2N6841a Rf Firmware N6854a FirmwareJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files. |
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an attacker to read arbitrary files from the file system. |
1Xinje 1Xd/e Series Plc Program Tool Jun 17, 2026 May 11, 2022 N/A· v4 7.3 HIGH· v3 6.0 MEDIUM· v2 A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be tri...Show more |
1Cisco 1Unified Communications Manager Jun 17, 2026 Apr 21, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated...Show more |
1Bbraun 2Datamodule Compactplus SpacecomJun 17, 2026 Apr 14, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary f...Show more |
1Sonicwall 5Sma 210 Firmware Sma 410 FirmwareSma 500v Firmware+2 moreJun 17, 2026 Apr 13, 2022 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA applia...Show more |
1Cisco 1Telepresence Video Communication Server Jun 17, 2026 Apr 6, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write pri...Show more |
1Cisco 1Telepresence Video Communication Server Jun 17, 2026 Apr 6, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read/write pri...Show more |