CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,205 vulnerabilities with CWE-22
CVE-2023-6407
MEDIUM
Schneider Electric Easy UPS Online Monitoring Software <= 2.6-ga-01-23248 - Path Traversal
CVSS 5.3
CVE-2023-43586
HIGH
Zoom Desktop Client for Windows - Privilege Escalation
CVSS 7.3
CVE-2023-47624
HIGH
audiobookshelf < 2.4.3 - Path Traversal via HLS Endpoint
CVSS 7.5
CVE-2023-44251
HIGH
FortiWAN 5.1.1-5.1.2 and 5.2.0-5.2.1 - Authenticated Path Traversal and Arbitrary File Deletion
CVSS 8.3
CVE-2023-6753
HIGH
MLflow < 2.9.2 - Path Traversal
CVSS 8.8
CVE-2023-49089
HIGH
Umbraco <8.18.10-12.3.0 - Path Traversal
CVSS 7.7
CVE-2023-28465
HIGH
HL7 FHIR Core Libraries <5.6.106 - Path Traversal
CVSS 7.5
CVE-2023-46455
HIGH
GL.iNET GL-AR300M <4.3.7 - Path Traversal
CVSS 7.5
CVE-2023-45316
HIGH
Mattermost < 7.8.14 - Cross-Site Request Forgery via Telemetry Run ID Path Traversal
CVSS 7.3
CVE-2023-49058
LOW
SAP Master Data Governance File Upload - Path Traversal
CVSS 3.5
CVE-2023-36654
MEDIUM
ProLion CryptoSpike 3.0.15P2 - Path Traversal
CVSS 6.5
CVE-2023-50449
HIGH
JFinalCMS 5.0.0 - Path Traversal via File Download fileKey Parameter
CVSS 7.5
CVE-2023-6120
MEDIUM
Welcart e-Commerce <2.9.6 - Path Traversal
CVSS 4.1
CVE-2023-49788
HIGH
Collaboraoffice Richdocumentscode < 23.5.602 - Path Traversal
CVSS 7.2
CVE-2023-46497
MEDIUM
EverShop <1.0.0-rc.8 - Path Traversal
CVSS 5.4
CVE-2023-46496
HIGH
EverShop <1.0.0-rc.8 - Path Traversal
CVSS 8.3
CVE-2023-46493
MEDIUM
EverShop <1.0.0-rc.8 - Path Traversal
CVSS 5.3
CVE-2023-6577
MEDIUM
Byzoro PatrolFlow <20231126 - Path Traversal
CVSS 4.3
CVE-2023-47440
MEDIUM
Gladys Assistant < 4.30.0 - Authenticated Path Traversal
CVSS 6.5
CVE-2023-33411
HIGH
Supermicro IPMI <3.17.02 - Path Traversal
CVSS 7.5
CVE-2023-46307
HIGH
etcd-browser <87ae63d75260 - Path Traversal
CVSS 7.5
CVE-2023-6458
HIGH
Mattermost < 7.8.14, 8.1.5, 9.1.2 - Client-Side Path Traversal via Route Parameters
CVSS 7.1
CVE-2023-5105
MEDIUM
WordPress Plugin <22.6 - Auth Bypass
CVSS 6.5
CVE-2023-44306
MEDIUM
Dell DM5500 Firmware < 5.14.0.0 - Path Traversal and Arbitrary File Write
CVSS 6.5
CVE-2023-49108
HIGH
RakRak Document Plus <6.4.0.7 - Path Traversal
CVSS 8.8
Details
Vulnerabilities
9,205
Exploit Likelihood
High