CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,161 vulnerabilities with CWE-22
CVE-2024-32163
MEDIUM
CMSeasy 7.7.7.9 - Remote Code Execution
CVSS 6.4
CVE-2024-28073
HIGH
SolarWinds Serv-U < 15.4.2 - Authenticated Directory Traversal Remote Code Execution
CVSS 8.4
CVE-2024-1132
HIGH
Keycloak >=21.1.0 <22.0.10 - Open Redirect via Wildcard Valid Redirect URIs
CVSS 8.1
CVE-2024-32024
MEDIUM
kohya_ss 22.6.1-23.1.5 - Path Traversal in add_pre_postfix Function
CVSS 6.5
CVE-2024-32023
MEDIUM
kohya_ss 22.6.1-23.1.5 - Path Traversal via find_and_replace Function
CVSS 6.5
CVE-2024-31451
MEDIUM
DocsGPT < 0.8.1 - Unauthenticated Limited File Write in routes.py
CVSS 5.3
CVE-2024-3573
CRITICAL
MLflow < 2.10.0 - Local File Inclusion via URI Scheme Parsing Bypass
CVSS 9.3
CVE-2024-3571
HIGH
langchain-ai/langchain - Path Traversal
CVSS 8.8
CVE-2024-1961
HIGH
vertaai/modeldb < latest - Path Traversal and Remote Code Execution via Artifact Path Parameter
CVSS 8.8
CVE-2024-1594
HIGH
MLflow - Path Traversal via Artifact Location URI Fragment
CVSS 7.5
CVE-2024-1593
HIGH
MLflow - Path Traversal via Semicolon Parameter Smuggling
CVSS 7.5
CVE-2024-1560
HIGH
lfprojects mlflow < 2.9.2 - Path Traversal via Double Decoding in Artifact Deletion
CVSS 8.1
CVE-2024-1558
HIGH
MLflow < 2.12.1 - Path Traversal via Source Parameter in _create_model_version()
CVSS 7.5
CVE-2024-1483
HIGH
mlflow < 2.12.1 - Path Traversal via Artifact Location and Source Parameters
CVSS 7.5
CVE-2024-3783
HIGH
WBSAirback 21.02.04 - Path Traversal
CVSS 7.7
CVE-2024-3737
MEDIUM
nginxwebui < 4.2.4 - Path Traversal via dir Argument in findCountByQuery
CVSS 6.3
CVE-2024-31462
MEDIUM
Stable-diffusion-webui <1.7.0 - Path Traversal
CVSS 6.3
CVE-2024-32005
HIGH
NiceGUI <1.4.21 - Local File Inclusion
CVSS 8.2
CVE-2024-3686
MEDIUM
DedeCMS 5.7.112-UTF8 - Path Traversal via update_guide.php files Parameter
CVSS 4.3
CVE-2024-31818
CRITICAL
derbynet 9.0 - Remote Code Execution via Kiosk Page Parameter Path Traversal
CVSS 9.8
CVE-2024-29502
MEDIUM
Secure Lockdown Multi Application Edition <v2.00.219 - Info Disclosure
CVSS 6.5
CVE-2024-2221
CRITICAL
qdrant - Path Traversal and Arbitrary File Write via Snapshot Upload Endpoint
CVSS 9.8
CVE-2024-1728
HIGH
gradio 4.18.0-4.19.2 - Path Traversal and Arbitrary File Read via UploadButton Queue Join Endpoint
CVSS 7.5
CVE-2024-1511
CRITICAL
lollms_web_ui - Unauthenticated Path Traversal and Arbitrary File Write via Inadequate File Path Validation
CVSS 9.8
CVE-2024-31287
MEDIUM
Media Library Folders < 8.1.8 - Path Traversal
CVSS 6.5
Details
Vulnerabilities
9,161
Exploit Likelihood
High