CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,168 vulnerabilities with CWE-22
CVE-2023-45723
HIGH
HCL DRYiCE MyXalytics - Path Traversal via File Upload Endpoint
CVSS 7.6
CVE-2023-45722
HIGH
HCL DRYiCE MyXalytics - Path Traversal and Arbitrary File Read
CVSS 8.8
CVE-2023-41780
MEDIUM
ZTE ZXCLOUD iRAI < 7.23.32 - Unauthenticated DLL Loading Path Traversal
CVSS 6.4
CVE-2023-7114
HIGH
Mattermost < 2.10.1 - Cross-Site Request Forgery via Deeplink Path
CVSS 7.1
CVE-2023-52085
LOW
Winter <1.2.3 - Local File Inclusion
CVSS 3.3
CVE-2023-7134
MEDIUM
SourceCodester Medicine Tracking System 1.0 - Path Traversal via Page Parameter
CVSS 6.3
CVE-2023-50255
CRITICAL
deepin-compressor < 5.12.21 - Path Traversal and Remote Code Execution via Crafted Archive
CVSS 9.3
CVE-2023-6190
CRITICAL
University Information Management System <30.11.2023 - Path Traversal
CVSS 9.8
CVE-2023-5991
CRITICAL
Hotel Booking Lite < 4.8.5 - Unauthenticated Path Traversal and Arbitrary File Deletion
CVSS 9.8
CVE-2023-5672
MEDIUM
WP Mail Log < 1.1.3 - Local File Inclusion via Email Attachment Path Parameter
CVSS 6.5
CVE-2023-30451
MEDIUM
TYPO3 11.5.24 - Authenticated Path Traversal via Filelist BaseURI Parameter
CVSS 4.9
CVE-2023-6972
CRITICAL
Backup Migration < 1.3.9 - Unauthenticated Path Traversal via HTTP Headers
CVSS 9.8
CVE-2023-51651
MEDIUM
AWS SDK for PHP <3.288.1 - Path Traversal
CVSS 6.0
CVE-2023-51449
MEDIUM
gradio < 4.11.0 - Path Traversal via /file Route
CVSS 5.6
CVE-2023-50731
CRITICAL
MindsDB < 23.11.4.1 - Path Traversal and Arbitrary File Write via File Upload Name Parameter
CVSS 9.1
CVE-2023-50254
CRITICAL
deepin_reader < 6.0.7 - Remote Code Execution via Crafted DOCX File
CVSS 9.3
CVE-2023-46645
MEDIUM
GitHub Enterprise Server <3.7.19-3.11.1 - Path Traversal
CVSS 6.8
CVE-2023-6562
HIGH
Kakadu SDK 4.4-8.4 - Path Traversal via JPX Fragment List Box
CVSS 7.5
CVE-2023-47702
MEDIUM
IBM Security Guardium Key Lifecycle Manager 4.2.0-4.2.0.2 - Path Traversal via URL Request
CVSS 4.3
CVE-2023-38126
HIGH
Softing edgeAggregator - Authenticated Remote Code Execution via Backup Zip File Path Traversal
CVSS 7.2
CVE-2023-6222
HIGH
Quttera Web Malware Scanner WP <3.4.2.1 - Path Traversal
CVSS 7.2
CVE-2023-46177
MEDIUM
IBM MQ Appliance <9.3 - Path Traversal
CVSS 6.5
CVE-2023-5115
MEDIUM
Ansible Automation Platform - Path Traversal via Malicious Role Symlink
CVSS 6.3
CVE-2023-6908
LOW
DFIRKuiper Kuiper 2.3.4 - Path Traversal in TAR Archive Handler
CVSS 3.1
CVE-2023-6900
MEDIUM
rmountjoy92 DashMachine 0.5-4 - Path Traversal via /settings/delete_file Endpoint
CVSS 4.6
Details
Vulnerabilities
9,168
Exploit Likelihood
High