CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,144 vulnerabilities with CWE-22
CVE-2024-47170 MEDIUM
agnai < 1.0.330 - Path Traversal via JSON Storage
CVSS 4.3
CVE-2024-46327 MEDIUM
VONETS VAP11G-300 v3.3.23.6.9 - Path Traversal via Http_handle Object
CVSS 5.7
CVE-2024-8704 HIGH
Advanced File Manager <5.2.8 - Authenticated RCE
CVSS 7.2
CVE-2024-44825 HIGH
InVesalius3 <3.1.99995 - Path Traversal
CVSS 7.5
CVE-2024-8941 HIGH
Scriptcase 9.4.019 - Unauthenticated Path Traversal via nm_edit_php_edit.php subpage Parameter
CVSS 7.5
CVE-2024-8291 MEDIUM
Concrete CMS <9.3.3 & <8.5.19 - Stored XSS
CVSS 4.8
CVE-2024-8671 CRITICAL
WooEvents - Calendar and Event Booking <4.1.2 - Path Traversal
CVSS 9.1
CVE-2024-43996 MEDIUM
ElementsKit Pro < 3.6.0 - PHP Local File Inclusion via Path Traversal
CVSS 6.5
CVE-2024-6786 MEDIUM
Moxa MXview One < 1.4.1 - Path Traversal via MQTT Message
CVSS 6.5
CVE-2024-46649 HIGH
eNMS < 4.7.1 - Path Traversal via Download Folder
CVSS 7.5
CVE-2024-46648 HIGH
eNMS 4.4.0-4.7.1 - Path Traversal via scan_folder
CVSS 7.5
CVE-2024-46647 MEDIUM
eNMS 4.4.0-4.7.1 - Path Traversal via upload_files
CVSS 6.5
CVE-2024-46646 MEDIUM
eNMS < 4.7.1 - Path Traversal via /download/file
CVSS 6.5
CVE-2024-46645 HIGH
eNMS 4.0.0 - Path Traversal via get_tree_files
CVSS 7.5
CVE-2024-46644 MEDIUM
eNMS 4.4.0-4.7.1 - Path Traversal via edit_file
CVSS 6.5
CVE-2024-9032 MEDIUM
Simple Forum-Discussion System 1.0 - Path Traversal via Page Parameter
CVSS 6.3
CVE-2024-33109 CRITICAL
Tiptel IP 286 Firmware < 2.61.13.10 - Path Traversal and Arbitrary File Write via Ringtone Upload
CVSS 9.9
CVE-2024-8963 CRITICAL KEV
Ivanti Endpoint Manager Cloud Services Appliance - Unauthenticated Path Traversal
CVSS 9.4
CVE-2024-46376 CRITICAL
Best House Rental Management System 1.0 - Arbitrary File Upload in update_account() Function
CVSS 9.8
CVE-2024-46375 CRITICAL
Best House Rental Management System 1.0 - Arbitrary File Upload in Signup Function
CVSS 9.8
CVE-2024-46987 HIGH
Camaleon CMS 2.8.0-2.8.1 - Authenticated Path Traversal via MediaController Download
CVSS 7.7
CVE-2024-46986 CRITICAL
Camaleon CMS < 2.8.2 - Authenticated Arbitrary File Write via MediaController Upload
CVSS 9.9
CVE-2024-45601 HIGH
Mesop >=0.9.0 <0.12.4 - Unauthorized File Access via Insufficient Input Validation
CVSS 7.5
CVE-2024-45816 MEDIUM
Backstage < 1.10.13 - Path Traversal in TechDocs Storage Provider
CVSS 6.5
CVE-2024-45604 MEDIUM
Contao < 4.13.49 - Authenticated Path Traversal in File Selector Widget
CVSS 4.3
Details
Vulnerabilities 9,144
Exploit Likelihood High