CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,152 vulnerabilities with CWE-22
CVE-2024-7741
MEDIUM
ltcms 1.0.20 - Path Traversal via API Endpoint
CVSS 5.3
CVE-2024-7738
LOW
yzane vscode-markdown-pdf <1.5.0 - Path Traversal
CVSS 3.3
CVE-2024-6618
HIGH
Ocean Data Systems Dream Report - Path Traversal
CVE-2024-43165
MEDIUM
Rashid87 WPSection <1.3.8 - Path Traversal
CVSS 6.5
CVE-2024-43140
HIGH
G5Theme Ultimate Bootstrap Elements <1.4.4 - Path Traversal
CVSS 7.5
CVE-2024-43138
MEDIUM
MagePeople Team Event Manager <4.2.1 - Path Traversal
CVSS 6.5
CVE-2024-43135
HIGH
Themewinter WPCafe <2.2.28 - Path Traversal
CVSS 7.5
CVE-2024-43129
MEDIUM
WPDeveloper BetterDocs <3.5.8 - Path Traversal
CVSS 6.5
CVE-2024-39651
HIGH
WooCommerce PDF Vouchers < 4.9.5 - Unauthenticated Path Traversal and Arbitrary File Deletion
CVSS 8.6
CVE-2024-41938
MEDIUM
SINEC NMS < 3.0 - Authenticated Path Traversal via ImportCertificate Function
CVSS 5.5
CVE-2024-42474
MEDIUM
Streamlit < 1.37.0 - Path Traversal via Static File Sharing Feature
CVSS 6.5
CVE-2024-42485
HIGH
Filament Excel <v2.3.3 - Path Traversal
CVSS 7.5
CVE-2024-33535
HIGH
Zimbra Collaboration 9.0-10.0 < 10.0.8 - Unauthenticated Local File Inclusion via Packages Parameter
CVSS 7.5
CVE-2024-7693
HIGH
raidenmaild < 5.0.2 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2024-7399
HIGH
KEV
Samsung MagicINFO 9 Server Remote Code Execution (CVE-2024-7399)
CVSS 8.8
CVE-2024-6759
MEDIUM
FreeBSD < 13.0 - Path Traversal via NFS Filename Sanitization Bypass
CVSS 5.3
CVE-2024-42469
CRITICAL
openHAB < 4.2.1 - Unauthenticated Path Traversal and Arbitrary File Write via CometVisu File System Endpoint
CVSS 9.8
CVE-2024-42468
MEDIUM
CometVisuServlet <4.2.1 - Path Traversal
CVSS 5.3
CVE-2024-41936
HIGH
Vonets Industrial WiFi Bridge Firmware < 3.3.23.6.9 - Unauthenticated Path Traversal and Authentication Bypass
CVSS 7.5
CVE-2024-21877
MEDIUM
Enphase IQ Gateway Firmware 4.0-8.0 and < 8.2.4225 - Authenticated Path Traversal via URL Parameter
CVSS 6.5
CVE-2024-21876
CRITICAL
Enphase IQ Gateway Firmware 4.0-8.2.4225 - Unauthenticated Path Traversal and Arbitrary File Write via URL Parameter
CVSS 9.1
CVE-2024-0113
HIGH
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC - Path Traversal via Web Support CGI URI
CVSS 7.5
CVE-2024-42408
MEDIUM
dorsettcontrols infoscan - Path Traversal via Client Download Page Interception
CVSS 5.3
CVE-2024-6707
HIGH
Web Server <version - Path Traversal
CVSS 8.8
CVE-2024-7061
MEDIUM
Okta Verify for Windows < 5.0.2 - Privilege Escalation via DLL Hijacking
CVSS 5.5
Details
Vulnerabilities
9,152
Exploit Likelihood
High