CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,158 vulnerabilities with CWE-22
CVE-2024-5821 MEDIUM
stitionai/devika - Path Traversal via Misspelled File Name Correction
CVSS 6.2
CVE-2024-5866 MEDIUM
Delinea Privileged Access Service < 22.3 - Path Traversal
CVSS 5.0
CVE-2024-5865 HIGH
Delinea Privileged Access Service < 22.3 - Path Traversal and Arbitrary File Read
CVSS 7.7
CVE-2024-5349 HIGH
LA-Studio Element Kit for Elementor <1.3.8.1 - Code Injection
CVSS 8.8
CVE-2024-36991 HIGH
Splunk 9.0.0-9.0.9 - Path Traversal via /modules/messaging/ Endpoint
CVSS 7.5
CVE-2024-24749 HIGH
GeoServer <2.23.5-2.24.3 - Info Disclosure
CVSS 7.5
CVE-2024-36059 CRITICAL
Kalkitech ASE <2.3.5 - Path Traversal
CVSS 9.4
CVE-2024-6127 CRITICAL
PowerShellEmpire Arbitrary File Upload (Skywalker)
CVSS 9.8
CVE-2024-6090 HIGH
gaizhenbiao/chuanhuchatgpt 20240410 - Path Traversal and Denial of Service via Chat History Deletion
CVSS 7.5
CVE-2024-6085 HIGH
lollms v9.6 - Unauthenticated Path Traversal and Arbitrary File Write via XTTS Server Root Folder Manipulation
CVSS 8.6
CVE-2024-5980 CRITICAL
lightning-ai/pytorch-lightning 2.2.4-2.3.2 - Path Traversal and Arbitrary File Write via Tar.gz Plugin Extraction
CVSS 9.8
CVE-2024-5824 HIGH
parisneo/lollms < 9.5.0 - Path Traversal and Remote Code Execution via /set_personality_config Endpoint
CVSS 7.4
CVE-2024-5548 HIGH
stitionai devika - Path Traversal via /api/download-project project_name Parameter
CVSS 7.5
CVE-2024-22232 HIGH
Salt File Server < unknown - Path Traversal
CVSS 7.7
CVE-2024-22231 MEDIUM
Salt < 3005.5 - Directory Traversal via Syndic Cache Directory Creation
CVSS 5.0
CVE-2024-5019 MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Arbitrary File Read via SessionController.CachedCSS
CVSS 5.3
CVE-2024-5018 MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Path Traversal via SessionController.LoadNMScript
CVSS 5.3
CVE-2024-5017 MEDIUM
WhatsUp Gold < 23.1.3 - Unauthenticated Path Traversal via AppProfileImport
CVSS 6.5
CVE-2024-4885 CRITICAL KEV
Progress WhatsUp Gold < 23.1.3 - Unauthenticated Remote Code Execution via ExportUtilities.Export.GetFileWithoutZip
CVSS 9.8
CVE-2024-4498 HIGH
parisneo/lollms-webui <latest - Path Traversal
CVSS 7.7
CVE-2024-32111 MEDIUM
WordPress <6.5.4-6.0.8 - Path Traversal
CVSS 5.0
CVE-2024-34313 CRITICAL
VPL Jail System <4.0.2 - Path Traversal
CVSS 9.8
CVE-2024-33881 MEDIUM
VirtoSoftware Virto Bulk File Download 5.5.44 - NTLMv2 Hash Leak via UNC Path Traversal
CVSS 5.3
CVE-2024-33879 CRITICAL
VirtoSoftware Virto Bulk File Download 5.5.44 - Path Traversal & Arbitrary File Deletion
CVSS 9.8
CVE-2024-37825 MEDIUM
EnvisionWare Computer Access & Reservation Control SelfCheck <1.0 -...
CVSS 5.4
Details
Vulnerabilities 9,158
Exploit Likelihood High