CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,161 vulnerabilities with CWE-22
CVE-2024-24482 CRITICAL
apktool < 2.9.3 - Path Traversal via ../ and /.. Sequences
CVSS 9.8
CVE-2024-22779 HIGH
Kihron ServerRPExposer <1.0.2 - RCE
CVSS 8.8
CVE-2024-22096 MEDIUM
Rapid SCADA <5.8.4 - Path Traversal
CVSS 6.5
CVE-2024-24756 HIGH
crafatar < 2.1.5 - Path Traversal via Public Directory Request
CVSS 7.5
CVE-2024-21852 HIGH
Rapid SCADA < 5.8.4 - Remote Code Execution via Zip Slip in Configuration File Unpacking
CVSS 8.8
CVE-2024-24569 MEDIUM
Pixee Java Code Security Toolkit <=1.1.1 - Path Traversal
CVSS 5.4
CVE-2024-23652 CRITICAL
BuildKit < 0.12.5 - Path Traversal via RUN --mount Feature
CVSS 10.0
CVE-2024-24579 MEDIUM
stereoscope <0.0.1 - Path Traversal
CVSS 5.3
CVE-2024-24565 MEDIUM
CrateDB Database - Arbitrary File Read
CVSS 5.7
CVE-2024-22523 HIGH
Qiyu iFair <23.8_ad0 - Path Traversal
CVSS 7.5
CVE-2024-23334 MEDIUM
aiohttp - Directory Traversal
CVSS 5.9
CVE-2024-23827 CRITICAL
nginx-ui - Unauthenticated Arbitrary File Write via Import Certificate Feature
CVSS 9.8
CVE-2024-23822 MEDIUM
Thruk < 3.12 - Path Traversal via File Upload Form
CVSS 5.4
CVE-2024-0989 MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Path Traversal
CVSS 5.4
CVE-2024-0697 MEDIUM
Backuply - WordPress <1.2.3 - Path Traversal
CVSS 6.5
CVE-2024-0402 CRITICAL
GitLab 16.0-16.8.1 Path Traversal & Arbitrary File Write via Workspace
CVSS 9.9
CVE-2024-0882 MEDIUM
qwdigital LinkWechat 5.1.0 - Path Traversal
CVSS 4.3
CVE-2024-23904 HIGH
Jenkins Log Command Plugin < 1.0.2 - Unauthenticated Arbitrary File Read via Command Parser
CVSS 7.5
CVE-2024-23899 MEDIUM
Jenkins Git Server Plugin < 99.va_0826a_b_cdfa_d - Arbitrary File Read via Command Parser
CVSS 6.5
CVE-2024-23897 CRITICAL KEV
Jenkins cli Ampersand Replacement Arbitrary File Read
CVSS 9.8
CVE-2024-22204 MEDIUM
Whoogle Search <0.8.3 - Path Traversal
CVSS 5.3
CVE-2024-23182 HIGH
a-blog cms < 2.9.0 - Authenticated Path Traversal and Arbitrary File Deletion
CVSS 8.1
CVE-2024-23340 MEDIUM
hono/node-server 1.3.0-1.4.1 - Path Traversal via serveStatic
CVSS 5.3
CVE-2024-23768 HIGH
Dremio 22.0.0-22.2.2 23.0.0-23.2.3 24.0.0-24.3.0 - Authenticated Path Traversal
CVSS 8.8
CVE-2024-0769 MEDIUM KEV
D-Link DIR-859 1.06B01 - Path Traversal
CVSS 5.3
Details
Vulnerabilities 9,161
Exploit Likelihood High