CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,168 vulnerabilities with CWE-22
CVE-2023-45723 HIGH
HCL DRYiCE MyXalytics - Path Traversal via File Upload Endpoint
CVSS 7.6
CVE-2023-45722 HIGH
HCL DRYiCE MyXalytics - Path Traversal and Arbitrary File Read
CVSS 8.8
CVE-2023-41780 MEDIUM
ZTE ZXCLOUD iRAI < 7.23.32 - Unauthenticated DLL Loading Path Traversal
CVSS 6.4
CVE-2023-7114 HIGH
Mattermost < 2.10.1 - Cross-Site Request Forgery via Deeplink Path
CVSS 7.1
CVE-2023-52085 LOW
Winter <1.2.3 - Local File Inclusion
CVSS 3.3
CVE-2023-7134 MEDIUM
SourceCodester Medicine Tracking System 1.0 - Path Traversal via Page Parameter
CVSS 6.3
CVE-2023-50255 CRITICAL
deepin-compressor < 5.12.21 - Path Traversal and Remote Code Execution via Crafted Archive
CVSS 9.3
CVE-2023-6190 CRITICAL
University Information Management System <30.11.2023 - Path Traversal
CVSS 9.8
CVE-2023-5991 CRITICAL
Hotel Booking Lite < 4.8.5 - Unauthenticated Path Traversal and Arbitrary File Deletion
CVSS 9.8
CVE-2023-5672 MEDIUM
WP Mail Log < 1.1.3 - Local File Inclusion via Email Attachment Path Parameter
CVSS 6.5
CVE-2023-30451 MEDIUM
TYPO3 11.5.24 - Authenticated Path Traversal via Filelist BaseURI Parameter
CVSS 4.9
CVE-2023-6972 CRITICAL
Backup Migration < 1.3.9 - Unauthenticated Path Traversal via HTTP Headers
CVSS 9.8
CVE-2023-51651 MEDIUM
AWS SDK for PHP <3.288.1 - Path Traversal
CVSS 6.0
CVE-2023-51449 MEDIUM
gradio < 4.11.0 - Path Traversal via /file Route
CVSS 5.6
CVE-2023-50731 CRITICAL
MindsDB < 23.11.4.1 - Path Traversal and Arbitrary File Write via File Upload Name Parameter
CVSS 9.1
CVE-2023-50254 CRITICAL
deepin_reader < 6.0.7 - Remote Code Execution via Crafted DOCX File
CVSS 9.3
CVE-2023-46645 MEDIUM
GitHub Enterprise Server <3.7.19-3.11.1 - Path Traversal
CVSS 6.8
CVE-2023-6562 HIGH
Kakadu SDK 4.4-8.4 - Path Traversal via JPX Fragment List Box
CVSS 7.5
CVE-2023-47702 MEDIUM
IBM Security Guardium Key Lifecycle Manager 4.2.0-4.2.0.2 - Path Traversal via URL Request
CVSS 4.3
CVE-2023-38126 HIGH
Softing edgeAggregator - Authenticated Remote Code Execution via Backup Zip File Path Traversal
CVSS 7.2
CVE-2023-6222 HIGH
Quttera Web Malware Scanner WP <3.4.2.1 - Path Traversal
CVSS 7.2
CVE-2023-46177 MEDIUM
IBM MQ Appliance <9.3 - Path Traversal
CVSS 6.5
CVE-2023-5115 MEDIUM
Ansible Automation Platform - Path Traversal via Malicious Role Symlink
CVSS 6.3
CVE-2023-6908 LOW
DFIRKuiper Kuiper 2.3.4 - Path Traversal in TAR Archive Handler
CVSS 3.1
CVE-2023-6900 MEDIUM
rmountjoy92 DashMachine 0.5-4 - Path Traversal via /settings/delete_file Endpoint
CVSS 4.6
Details
Vulnerabilities 9,168
Exploit Likelihood High