CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,161 vulnerabilities with CWE-22
CVE-2024-23540
MEDIUM
HCL BigFix Inventory - Path Traversal
CVSS 5.3
CVE-2024-20352
MEDIUM
Cisco Emergency Responder - Path Traversal
CVSS 4.9
CVE-2024-20348
HIGH
Cisco Nexus Dashboard Fabric Controller - Info Disclosure
CVSS 7.5
CVE-2024-29434
HIGH
Alldata v0.4.6 - Path Traversal via System Image Upload Interface
CVSS 8.3
CVE-2024-25944
MEDIUM
Dell OpenManage Enterprise < 4.0.1 - Unauthenticated Path Traversal
CVSS 5.7
CVE-2024-30492
MEDIUM
WebToffee Import Export <2.5.2 - Path Traversal
CVSS 4.3
CVE-2024-3078
MEDIUM
qdrant < 1.6.1/1.7.4/1.8.2 - Path Traversal in Full Snapshot REST API
CVSS 5.5
CVE-2024-0980
HIGH
Okta Verify for Windows < 4.10.7 - Arbitrary Code Execution via Auto-Update Service
CVSS 7.1
CVE-2024-28335
CRITICAL
Lektor < 3.3.11 - Remote Code Execution via DB Path Traversal
CVSS 9.1
CVE-2024-2210
MEDIUM
The Plus Addons for Elementor <5.4.1 - Code Injection
CVSS 6.4
CVE-2024-2203
MEDIUM
The Plus Addons for Elementor <5.4.1 - Code Injection
CVSS 6.4
CVE-2024-25136
HIGH
AutomationDirect C-MORE EA9 HMI - Path Traversal
CVSS 7.5
CVE-2024-29196
LOW
phpMyFAQ 3.2.5 - Authenticated Path Traversal via Attachment Upload
CVSS 3.8
CVE-2024-2863
MEDIUM
LG LED Assistant - Thumbnail Path Traversal File Upload
CVSS 5.3
CVE-2024-2227
CRITICAL
JavaServer Faces 2.2.20 - Path Traversal
CVSS 10.0
CVE-2024-28171
HIGH
diaenergie < 1.10.00.005 - Path Traversal and Arbitrary File Write
CVSS 8.1
CVE-2024-25567
HIGH
Deltaww DIAENERGIE <= 1.10.00.005 - Path Traversal
CVSS 8.1
CVE-2024-27921
HIGH
Grav < 1.7.45 - Path Traversal and Arbitrary File Write via File Upload
CVSS 8.8
CVE-2024-29180
HIGH
Webpack-dev-middleware <7.1.0, 6.1.2, 5.3.4 - Info Disclosure
CVSS 7.4
CVE-2024-1142
MEDIUM
Sonatype IQ Server <171 - Path Traversal
CVSS 5.4
CVE-2024-23721
HIGH
Draytek Vigor3910 Firmware < 4.3.2.5 - Path Traversal via process_post
CVSS 7.5
CVE-2024-21677
HIGH
Confluence Data Center and Server 6.13.0-7.19.19 - Unauthenticated Path Traversal
CVSS 8.8
CVE-2024-24043
MEDIUM
Speedy11CZ MCRPX <1.4.0 - Path Traversal
CVSS 5.5
CVE-2024-24042
HIGH
ARRP < 0.8.2 - Remote Code Execution via dumpDirect in RuntimeResourcePackImpl
CVSS 8.8
CVE-2024-27771
HIGH
Unitronics Unistream Unilogic -1.35.227 - Path Traversal
CVSS 8.8
Details
Vulnerabilities
9,161
Exploit Likelihood
High