CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,205 vulnerabilities with CWE-22
CVE-2023-37532 MEDIUM
HCL Commerce 9.1.8-9.1.13.2 - Path Traversal via Crafted URL
CVSS 5.8
CVE-2023-46122 LOW
sbt < 1.9.7 - Path Traversal and Arbitrary File Write via IO.unzip
CVSS 3.9
CVE-2023-44256 MEDIUM
FortiAnalyzer/FortiManager SSRF via Crafted HTTP Request
CVSS 6.5
CVE-2023-5414 CRITICAL
Icegram Express <= 5.6.23 - Authenticated Path Traversal via show_es_logs Function
CVSS 9.1
CVE-2023-4274 HIGH
Migration, Backup, Staging - WPvivid < 0.9.90 - Authenticated Directory Traversal via Arbitrary Directory Deletion
CVSS 8.7
CVE-2023-45823 HIGH
Artifact Hub < 1.16.0 - Path Traversal via Symbolic Link Processing
CVSS 7.5
CVE-2023-45278 CRITICAL
Yamcs 5.8.6 - Path Traversal via Storage API DELETE Request
CVSS 9.1
CVE-2023-45277 HIGH
Yamcs 5.8.6 - Path Traversal in Storage API
CVSS 7.5
CVE-2023-35187 HIGH
SolarWinds Access Rights Manager < 2023.2.0.73 - Unauthenticated Path Traversal and Remote Code Execution
CVSS 8.8
CVE-2023-35185 MEDIUM
SolarWinds Access Rights Manager < 2023.2.0.73 - Directory Traversal Remote Code Execution
CVSS 6.8
CVE-2023-31046 MEDIUM
PaperCut NG <22.1.1 - Path Traversal
CVSS 6.5
CVE-2023-5241 CRITICAL
WPBot AI ChatBot <=4.8.9,4.9.2 - Authenticated Directory Traversal
CVSS 9.6
CVE-2023-5212 CRITICAL
WPBot AI ChatBot <=4.8.9/4.9.2 - Authenticated Arbitrary File Deletion
CVSS 9.6
CVE-2023-43801 MEDIUM
Arduino Create Agent <1.3.3 - Privilege Escalation
CVSS 6.1
CVE-2023-43803 MEDIUM
Arduino Create Agent <1.3.3 - File Deletion
CVSS 6.1
CVE-2023-43802 HIGH
Arduino Create Agent <1.3.3 - Privilege Escalation
CVSS 7.1
CVE-2023-45383 HIGH
SoNice Etiquetage < 2.5.9 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2023-39332 CRITICAL
Node.js 20.0.0-20.7.9 - Path Traversal via Uint8Array Path Handling
CVSS 9.8
CVE-2023-39331 HIGH
Node.js 20.0.0-20.8.1 - Path Traversal via Experimental Permission Model
CVSS 7.5
CVE-2023-34208 MEDIUM
EasyUse MailHunter Ultimate < 2023 - Authenticated Path Traversal via Crafted ZIP Archive
CVSS 6.5
CVE-2023-43121 HIGH
Chalet EXOS <32.5.1.5-31.7.2 - Path Traversal
CVSS 7.5
CVE-2023-45689 MEDIUM
Titan MFT and SFTP Server < 2.0.18 - Authenticated Path Traversal
CVSS 6.5
CVE-2023-45688 MEDIUM
Titan MFT and SFTP Server < 2.0.18 - Authenticated Path Traversal via FTP SIZE Command
CVSS 4.3
CVE-2023-45686 HIGH
Titan MFT and Titan SFTP < 2.0.18 - Authenticated Path Traversal via WebDAV
CVSS 7.2
CVE-2023-45685 CRITICAL
South River Technologies Titan MFT and SFTP Servers < 2.0.18 - Authenticated Path Traversal via Zip Archive Extraction
CVSS 9.1
Details
Vulnerabilities 9,205
Exploit Likelihood High