CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,161 vulnerabilities with CWE-22
CVE-2024-31240
HIGH
InfoTheme WP Poll Maker <= 3.1 - Path Traversal
CVSS 7.7
CVE-2024-2654
MEDIUM
WordPress File Manager <7.2.5 - Path Traversal
CVSS 6.8
CVE-2024-1974
HIGH
HT Mega - Absolute Addons For Elementor <2.4.6 - Path Traversal
CVSS 8.8
CVE-2024-1790
MEDIUM
WordPress Infinite Scroll - Ajax Load More <7.0.1 - Path Traversal
CVSS 4.9
CVE-2024-31457
HIGH
gin-vue-admin < 0.0.0-20240409100909-b1b7427c6ea6 - Directory Traversal & Arbitrary Code Execution
CVSS 7.7
CVE-2024-29053
HIGH
Microsoft Defender for IoT < 24.1.3 - Remote Code Execution
CVSS 8.8
CVE-2024-31487
MEDIUM
FortiSandbox 2.4.0-4.2.6, 4.4.0-4.4.4 - Path Traversal via Crafted HTTP Requests
CVSS 5.9
CVE-2024-23671
HIGH
Fortinet FortiSandbox 4.0.0-4.0.4, 4.2.1-4.2.6, 4.4.0-4.4.3 - Path Traversal via Crafted HTTP Requests
CVSS 8.1
CVE-2024-2224
HIGH
Bitdefender Endpoint Security and GravityZone Control Center - Remote Code Execution via UpdateServer Path Traversal
CVSS 8.1
CVE-2024-31978
HIGH
SINEC NMS < V2.0 SP2 - Path Traversal
CVSS 7.6
CVE-2024-31860
MEDIUM
Apache Zeppelin <0.11.0 - Info Disclosure
CVSS 6.5
CVE-2024-30417
HIGH
Huawei EMUI and HarmonyOS - Path Traversal via Bluetooth Sharing Module
CVSS 7.5
CVE-2024-0406
MEDIUM
mholt/archiver 3.0.0-4.0.0 - Path Traversal and Arbitrary File Write via Crafted Tar Archive
CVSS 6.1
CVE-2024-22328
HIGH
IBM Maximo Application Suite <8.11 - Path Traversal
CVSS 7.5
CVE-2024-31851
HIGH
CData Sync < 23.4.8843 - Path Traversal
CVSS 8.6
CVE-2024-31850
HIGH
CData Arc < 23.4.8839 - Path Traversal
CVSS 8.6
CVE-2024-31849
CRITICAL
CData Connect < 23.4.8846 - Path Traversal
CVSS 9.8
CVE-2024-31848
CRITICAL
CData API Server < 23.4.8844 - Path Traversal
CVSS 9.8
CVE-2024-31220
HIGH
lizardbyte/sunshine 0.16.0-0.17.9 - Unauthenticated Path Traversal via node_modules Endpoint
CVSS 7.3
CVE-2024-29672
HIGH
zly2006 Reden <0.2.514 - Path Traversal
CVSS 8.8
CVE-2024-3311
MEDIUM
Dreamer CMS <4.1.3.0 - Path Traversal
CVSS 6.3
CVE-2024-30270
MEDIUM
mailcow < 2024-04 - Authenticated Path Traversal and Arbitrary Code Execution via rspamd_maps()
CVSS 6.2
CVE-2024-30254
MEDIUM
mesonlsp < 4.1.4 - Arbitrary File Write via Crafted Project or --full Mode
CVSS 5.8
CVE-2024-25693
CRITICAL
Esri Portal for ArcGIS <= 11.2 - Authenticated Path Traversal
CVSS 9.9
CVE-2024-27575
HIGH
INOTEC Sicherheitstechnik WebServer CPS220/64 <3.3.19 - Path Traversal
CVSS 7.5
Details
Vulnerabilities
9,161
Exploit Likelihood
High