CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,158 vulnerabilities with CWE-22
CVE-2024-5821
MEDIUM
stitionai/devika - Path Traversal via Misspelled File Name Correction
CVSS 6.2
CVE-2024-5866
MEDIUM
Delinea Privileged Access Service < 22.3 - Path Traversal
CVSS 5.0
CVE-2024-5865
HIGH
Delinea Privileged Access Service < 22.3 - Path Traversal and Arbitrary File Read
CVSS 7.7
CVE-2024-5349
HIGH
LA-Studio Element Kit for Elementor <1.3.8.1 - Code Injection
CVSS 8.8
CVE-2024-36991
HIGH
Splunk 9.0.0-9.0.9 - Path Traversal via /modules/messaging/ Endpoint
CVSS 7.5
CVE-2024-24749
HIGH
GeoServer <2.23.5-2.24.3 - Info Disclosure
CVSS 7.5
CVE-2024-36059
CRITICAL
Kalkitech ASE <2.3.5 - Path Traversal
CVSS 9.4
CVE-2024-6127
CRITICAL
PowerShellEmpire Arbitrary File Upload (Skywalker)
CVSS 9.8
CVE-2024-6090
HIGH
gaizhenbiao/chuanhuchatgpt 20240410 - Path Traversal and Denial of Service via Chat History Deletion
CVSS 7.5
CVE-2024-6085
HIGH
lollms v9.6 - Unauthenticated Path Traversal and Arbitrary File Write via XTTS Server Root Folder Manipulation
CVSS 8.6
CVE-2024-5980
CRITICAL
lightning-ai/pytorch-lightning 2.2.4-2.3.2 - Path Traversal and Arbitrary File Write via Tar.gz Plugin Extraction
CVSS 9.8
CVE-2024-5824
HIGH
parisneo/lollms < 9.5.0 - Path Traversal and Remote Code Execution via /set_personality_config Endpoint
CVSS 7.4
CVE-2024-5548
HIGH
stitionai devika - Path Traversal via /api/download-project project_name Parameter
CVSS 7.5
CVE-2024-22232
HIGH
Salt File Server < unknown - Path Traversal
CVSS 7.7
CVE-2024-22231
MEDIUM
Salt < 3005.5 - Directory Traversal via Syndic Cache Directory Creation
CVSS 5.0
CVE-2024-5019
MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Arbitrary File Read via SessionController.CachedCSS
CVSS 5.3
CVE-2024-5018
MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Path Traversal via SessionController.LoadNMScript
CVSS 5.3
CVE-2024-5017
MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Path Traversal via AppProfileImport
CVSS 6.5
CVE-2024-4885
CRITICAL
KEV
Progress WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via ExportUtilities.Export.GetFileWithoutZip
CVSS 9.8
CVE-2024-4498
HIGH
parisneo/lollms-webui <latest - Path Traversal
CVSS 7.7
CVE-2024-32111
MEDIUM
WordPress <6.5.4-6.0.8 - Path Traversal
CVSS 5.0
CVE-2024-34313
CRITICAL
VPL Jail System <4.0.2 - Path Traversal
CVSS 9.8
CVE-2024-33881
MEDIUM
VirtoSoftware Virto Bulk File Download 5.5.44 - NTLMv2 Hash Leak via UNC Path Traversal
CVSS 5.3
CVE-2024-33879
CRITICAL
VirtoSoftware Virto Bulk File Download 5.5.44 - Path Traversal & Arbitrary File Deletion
CVSS 9.8
CVE-2024-37825
MEDIUM
EnvisionWare Computer Access & Reservation Control SelfCheck <1.0 -...
CVSS 5.4
Details
Vulnerabilities
9,158
Exploit Likelihood
High