CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,168 vulnerabilities with CWE-22
CVE-2023-50885
MEDIUM
AGILELOGIX Store Locator <1.4.14 - Path Traversal
CVSS 6.8
CVE-2023-47843
HIGH
CataBlog <= 1.7.0 - Path Traversal and Arbitrary File Deletion
CVSS 7.6
CVE-2023-3675
MEDIUM
Secomea GateManager <11.0.623373051 - Path Traversal
CVSS 6.5
CVE-2023-38511
MEDIUM
iTop 3.0.0-3.0.3 - Path Traversal and Information Disclosure via Dashboard Editor
CVSS 5.0
CVE-2023-52144
MEDIUM
RexTheme Product Feed Manager <7.3.15 - Path Traversal
CVSS 5.5
CVE-2023-47541
MEDIUM
FortiSandbox 2.0-4.2.6, 4.4.0-4.4.2 - Path Traversal via CLI
CVSS 6.7
CVE-2023-52544
MEDIUM
Huawei EMUI and HarmonyOS - Path Traversal via Email Module
CVSS 4.3
CVE-2023-35812
MEDIUM
OpenSSH <7.4p1-22.78.amzn1,7.4p1-22.amzn2.0.2 - Info Disclosure
CVSS 5.3
CVE-2023-25341
MEDIUM
Ladle dev server <2.5.1 - Path Traversal
CVSS 6.5
CVE-2023-42947
HIGH
macOS Monterey <12.7.2 - Privilege Escalation
CVSS 8.6
CVE-2023-0582
HIGH
ForgeRock Access Management < 7.3.0, < 7.2.1, < 7.1.4, <= 7.0.2 - Path Traversal and Authorization Bypass
CVSS 8.1
CVE-2023-52623
MEDIUM
Linux Kernel 4.9-4.19.307 - Use-After-Free in SUNRPC Multipath XPRT Handling
CVSS 5.5
CVE-2023-41973
HIGH
Zscaler Client Connector < 4.3.0.121 - Path Traversal via TrayManager Config Parameter
CVSS 7.3
CVE-2023-41877
HIGH
GeoServer < 2.23.4 - Authenticated Path Traversal via Log File Location Misconfiguration
CVSS 7.2
CVE-2023-40279
HIGH
OpenClinic GA 5.247.01 - Authenticated Path Traversal via Page Parameter
CVSS 7.5
CVE-2023-40280
HIGH
OpenClinic GA 5.247.01 - Authenticated Path Traversal via Page Parameter in popup.jsp
CVSS 7.5
CVE-2023-40747
HIGH
A.K.I Software's PMailServer/PMailServer2 - Path Traversal
CVSS 7.5
CVE-2023-40160
LOW
A.K.I Software PMailServer/PMailServer2 - Path Traversal
CVSS 3.7
CVE-2023-6825
CRITICAL
File Manager (Free <=7.2.1, Pro <=8.3.4) - Directory Traversal & Arbitrary File Upload
CVSS 9.9
CVE-2023-47221
MEDIUM
QNAP Photo Station 6.4.0-6.4.1 - Authenticated Path Traversal
CVSS 5.5
CVE-2023-38366
MEDIUM
IBM Filenet Content Manager Component <5.5.11.0 - Path Traversal
CVSS 5.3
CVE-2023-7207
MEDIUM
GNU cpio - Path Traversal via --no-absolute-filenames Option
CVSS 4.9
CVE-2023-49960
HIGH
indu-sol PROFINET-INspektor NT < 2.4.0 - Path Traversal and Arbitrary File Write via httpuploadd Upload Endpoint
CVSS 7.5
CVE-2023-24416
MEDIUM
Arne Franken All In One Favicon <4.7 - Path Traversal
CVSS 6.8
CVE-2023-50955
LOW
IBM InfoSphere Information Server 11.7 - Authenticated Path Traversal
CVSS 2.4
Details
Vulnerabilities
9,168
Exploit Likelihood
High