CWE-25
12 CVEs • Abstraction: Variant
Path Traversal: '/../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.
CVEs (12)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any aut...Show more |
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution. |
Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability. |
A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownlo...Show more |
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor...Show more |
Franklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attacker to access sensitive files on the system.
|
Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While hand...Show more |
1Biges 9Vg 255 Bv Firmware Vg 255 Df FirmwareVg 255a Bf Firmware+6 moreJun 17, 2026 Jan 26, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal.
This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C. |
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is c...Show more |
1Neutron 17Ipc2224 Sr3 Npf 36 Firmware Ipc2624 Sr3 Npf 36 FirmwareNeu Ipb210 28 Firmware+14 moreJun 17, 2026 Nov 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal.
This issue affects IP Camera: before b1130.1.0.1. |
1Cisco 4Sd Wan Sd Wan Vbond OrchestratorSd Wan Vmanage+1 moreJun 17, 2026 Sep 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the appl...Show more |
1Cisco 5Catalyst Sd Wan Manager Sd WanSd Wan Vbond Orchestrator+2 moreJun 17, 2026 Sep 30, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CL...Show more |