CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,161 vulnerabilities with CWE-22
CVE-2024-32163 MEDIUM
CMSeasy 7.7.7.9 - Remote Code Execution
CVSS 6.4
CVE-2024-28073 HIGH
SolarWinds Serv-U < 15.4.2 - Authenticated Directory Traversal Remote Code Execution
CVSS 8.4
CVE-2024-1132 HIGH
Keycloak >=21.1.0 <22.0.10 - Open Redirect via Wildcard Valid Redirect URIs
CVSS 8.1
CVE-2024-32024 MEDIUM
kohya_ss 22.6.1-23.1.5 - Path Traversal in add_pre_postfix Function
CVSS 6.5
CVE-2024-32023 MEDIUM
kohya_ss 22.6.1-23.1.5 - Path Traversal via find_and_replace Function
CVSS 6.5
CVE-2024-31451 MEDIUM
DocsGPT < 0.8.1 - Unauthenticated Limited File Write in routes.py
CVSS 5.3
CVE-2024-3573 CRITICAL
MLflow < 2.10.0 - Local File Inclusion via URI Scheme Parsing Bypass
CVSS 9.3
CVE-2024-3571 HIGH
langchain-ai/langchain - Path Traversal
CVSS 8.8
CVE-2024-1961 HIGH
vertaai/modeldb < latest - Path Traversal and Remote Code Execution via Artifact Path Parameter
CVSS 8.8
CVE-2024-1594 HIGH
MLflow - Path Traversal via Artifact Location URI Fragment
CVSS 7.5
CVE-2024-1593 HIGH
MLflow - Path Traversal via Semicolon Parameter Smuggling
CVSS 7.5
CVE-2024-1560 HIGH
lfprojects mlflow < 2.9.2 - Path Traversal via Double Decoding in Artifact Deletion
CVSS 8.1
CVE-2024-1558 HIGH
MLflow < 2.12.1 - Path Traversal via Source Parameter in _create_model_version()
CVSS 7.5
CVE-2024-1483 HIGH
mlflow < 2.12.1 - Path Traversal via Artifact Location and Source Parameters
CVSS 7.5
CVE-2024-3783 HIGH
WBSAirback 21.02.04 - Path Traversal
CVSS 7.7
CVE-2024-3737 MEDIUM
nginxwebui < 4.2.4 - Path Traversal via dir Argument in findCountByQuery
CVSS 6.3
CVE-2024-31462 MEDIUM
Stable-diffusion-webui <1.7.0 - Path Traversal
CVSS 6.3
CVE-2024-32005 HIGH
NiceGUI <1.4.21 - Local File Inclusion
CVSS 8.2
CVE-2024-3686 MEDIUM
DedeCMS 5.7.112-UTF8 - Path Traversal via update_guide.php files Parameter
CVSS 4.3
CVE-2024-31818 CRITICAL
derbynet 9.0 - Remote Code Execution via Kiosk Page Parameter Path Traversal
CVSS 9.8
CVE-2024-29502 MEDIUM
Secure Lockdown Multi Application Edition <v2.00.219 - Info Disclosure
CVSS 6.5
CVE-2024-2221 CRITICAL
qdrant - Path Traversal and Arbitrary File Write via Snapshot Upload Endpoint
CVSS 9.8
CVE-2024-1728 HIGH
gradio 4.18.0-4.19.2 - Path Traversal and Arbitrary File Read via UploadButton Queue Join Endpoint
CVSS 7.5
CVE-2024-1511 CRITICAL
lollms_web_ui - Unauthenticated Path Traversal and Arbitrary File Write via Inadequate File Path Validation
CVSS 9.8
CVE-2024-31287 MEDIUM
Media Library Folders < 8.1.8 - Path Traversal
CVSS 6.5
Details
Vulnerabilities 9,161
Exploit Likelihood High