CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,205 vulnerabilities with CWE-22
CVE-2023-37532
MEDIUM
HCL Commerce 9.1.8-9.1.13.2 - Path Traversal via Crafted URL
CVSS 5.8
CVE-2023-46122
LOW
sbt < 1.9.7 - Path Traversal and Arbitrary File Write via IO.unzip
CVSS 3.9
CVE-2023-44256
MEDIUM
FortiAnalyzer/FortiManager SSRF via Crafted HTTP Request
CVSS 6.5
CVE-2023-5414
CRITICAL
Icegram Express <= 5.6.23 - Authenticated Path Traversal via show_es_logs Function
CVSS 9.1
CVE-2023-4274
HIGH
Migration, Backup, Staging - WPvivid < 0.9.90 - Authenticated Directory Traversal via Arbitrary Directory Deletion
CVSS 8.7
CVE-2023-45823
HIGH
Artifact Hub < 1.16.0 - Path Traversal via Symbolic Link Processing
CVSS 7.5
CVE-2023-45278
CRITICAL
Yamcs 5.8.6 - Path Traversal via Storage API DELETE Request
CVSS 9.1
CVE-2023-45277
HIGH
Yamcs 5.8.6 - Path Traversal in Storage API
CVSS 7.5
CVE-2023-35187
HIGH
SolarWinds Access Rights Manager < 2023.2.0.73 - Unauthenticated Path Traversal and Remote Code Execution
CVSS 8.8
CVE-2023-35185
MEDIUM
SolarWinds Access Rights Manager < 2023.2.0.73 - Directory Traversal Remote Code Execution
CVSS 6.8
CVE-2023-31046
MEDIUM
PaperCut NG <22.1.1 - Path Traversal
CVSS 6.5
CVE-2023-5241
CRITICAL
WPBot AI ChatBot <=4.8.9,4.9.2 - Authenticated Directory Traversal
CVSS 9.6
CVE-2023-5212
CRITICAL
WPBot AI ChatBot <=4.8.9/4.9.2 - Authenticated Arbitrary File Deletion
CVSS 9.6
CVE-2023-43801
MEDIUM
Arduino Create Agent <1.3.3 - Privilege Escalation
CVSS 6.1
CVE-2023-43803
MEDIUM
Arduino Create Agent <1.3.3 - File Deletion
CVSS 6.1
CVE-2023-43802
HIGH
Arduino Create Agent <1.3.3 - Privilege Escalation
CVSS 7.1
CVE-2023-45383
HIGH
SoNice Etiquetage < 2.5.9 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2023-39332
CRITICAL
Node.js 20.0.0-20.7.9 - Path Traversal via Uint8Array Path Handling
CVSS 9.8
CVE-2023-39331
HIGH
Node.js 20.0.0-20.8.1 - Path Traversal via Experimental Permission Model
CVSS 7.5
CVE-2023-34208
MEDIUM
EasyUse MailHunter Ultimate < 2023 - Authenticated Path Traversal via Crafted ZIP Archive
CVSS 6.5
CVE-2023-43121
HIGH
Chalet EXOS <32.5.1.5-31.7.2 - Path Traversal
CVSS 7.5
CVE-2023-45689
MEDIUM
Titan MFT and SFTP Server < 2.0.18 - Authenticated Path Traversal
CVSS 6.5
CVE-2023-45688
MEDIUM
Titan MFT and SFTP Server < 2.0.18 - Authenticated Path Traversal via FTP SIZE Command
CVSS 4.3
CVE-2023-45686
HIGH
Titan MFT and Titan SFTP < 2.0.18 - Authenticated Path Traversal via WebDAV
CVSS 7.2
CVE-2023-45685
CRITICAL
South River Technologies Titan MFT and SFTP Servers < 2.0.18 - Authenticated Path Traversal via Zip Archive Extraction
CVSS 9.1
Details
Vulnerabilities
9,205
Exploit Likelihood
High