CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,161 vulnerabilities with CWE-22
CVE-2024-5187
HIGH
ONNX 1.16.0 - Path Traversal and Arbitrary File Overwrite via Tar Extraction
CVSS 8.8
CVE-2024-4881
HIGH
lollms < 5.9.0 - Path Traversal via Backslash Handling in /user_infos Endpoint
CVSS 7.5
CVE-2024-4320
CRITICAL
lollms_web_ui - Remote Code Execution via Extension Install Name Parameter
CVSS 9.8
CVE-2024-3429
CRITICAL
lollms < 9.6 - Path Traversal via Insufficient Input Sanitization
CVSS 9.8
CVE-2024-3322
CRITICAL
Parisneo/lollms-webui <9.5 - Path Traversal
CVSS 9.8
CVE-2024-3234
CRITICAL
gaizhenbiao/chuanhuchatgpt < 20240305 - Path Traversal via Outdated Gradio Component
CVSS 9.8
CVE-2024-2928
HIGH
MLflow < 2.11.3 - Path Traversal
CVSS 7.5
CVE-2024-2624
CRITICAL
parisneo/lollms-webui - Path Traversal
CVSS 9.8
CVE-2024-2548
HIGH
lollms_web_ui < 9.5 - Path Traversal via User Infos Endpoint
CVSS 7.5
CVE-2024-2362
CRITICAL
lollms_web_ui 9.3 - Path Traversal and Arbitrary File Deletion via del_preset Endpoint
CVSS 9.1
CVE-2024-2360
CRITICAL
lollms_web_ui - Path Traversal and Remote Code Execution via Database and PDF LaTeX Path Settings
CVSS 9.8
CVE-2024-23793
MEDIUM
OTRS <7.0.49, 8.0.X, 2023.X, <2024.3.2 - Path Traversal
CVSS 6.3
CVE-2024-1873
CRITICAL
lollms_web_ui a9d16b0 - Path Traversal and Denial of Service via /select_database Endpoint
CVSS 9.1
CVE-2024-0520
HIGH
mlflow/mlflow <8.2.1 - Command Injection
CVSS 8.8
CVE-2024-5505
HIGH
NETGEAR ProSAFE NMS < 1.7.0.37 - Authenticated RCE via Path Traversal
CVSS 8.8
CVE-2024-4941
HIGH
gradio-app/gradio <4.25 - Local File Inclusion
CVSS 7.5
CVE-2024-2914
HIGH
deepjavalibrary/djl <0.27.0 - Path Traversal
CVSS 8.8
CVE-2024-34832
CRITICAL
CubeCart < 6.5.5 - Path Traversal and Arbitrary Code Execution via _g and node Parameters
CVSS 9.8
CVE-2024-28995
HIGH
KEV
SolarWinds Serv-U - Directory Traversal
CVSS 8.6
CVE-2024-5153
CRITICAL
Startklar Elementor Addons <1.7.15 - Path Traversal
CVSS 9.1
CVE-2024-5179
HIGH
Cowidgets - Elementor Addons <1.1.1 - Code Injection
CVSS 8.8
CVE-2024-35634
MEDIUM
Wow-Company Woocommerce - Recent Purchases < 1.0.1 - PHP Local File Inclusion via Path Traversal
CVSS 4.9
CVE-2024-34554
HIGH
Select-Themes Stockholm Core <2.4.1 - Path Traversal
CVSS 8.5
CVE-2024-34552
HIGH
Select-Themes Stockholm <9.6 - Path Traversal
CVSS 8.5
CVE-2024-34551
CRITICAL
Select-Themes Stockholm <9.6 - Path Traversal
CVSS 9.0
Details
Vulnerabilities
9,161
Exploit Likelihood
High