CWE-36
130 CVEs • Abstraction: Base
Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
CVEs (130)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 1Intersight Virtual Appliance Jun 17, 2026 Jul 22, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected sy...Show more |
1Cisco 1Intersight Virtual Appliance Jun 17, 2026 Jul 22, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected sy...Show more |
1Dell 1Wyse Management Suite Jun 17, 2026 Jul 15, 2021 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system. |
Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the...Show more |
Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the upd...Show more |
1Junhetec 1Omnidirectional Communication System Jun 17, 2026 May 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file. |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.5 HIGH· v3 9.4 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal a...Show more |
1Cisco 5Rv160 Vpn Router Firmware Rv160w Wireless Ac Vpn Router FirmwareRv260 Vpn Router Firmware+2 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.5 HIGH· v3 9.4 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal a...Show more |
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, th...Show more |
An Absolute Path Traversal issue was discovered in Advantech WebAccess Version 8.1 and prior. The absolute path traversal vulnerability has been identified, which may allow an attacker to traverse the file system to acce...Show more |