CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,205 vulnerabilities with CWE-22
CVE-2023-21415
MEDIUM
AXIS OS - Authenticated Path Traversal and Arbitrary File Deletion via VAPIX API overlay_del.cgi
CVSS 6.5
CVE-2023-5588
LOW
kphrx pleroma - Path Traversal in Pleroma.Emoji.Pack
CVSS 2.6
CVE-2023-38312
HIGH
Valve Counter-Strike 8684 - Path Traversal
CVSS 7.5
CVE-2023-45855
HIGH
qdPM 9.2 - Path Traversal via /uploads URI
CVSS 7.5
CVE-2023-32974
HIGH
QNAP QTS 5.1.0-5.1.0.2443, QuTS hero h5.1.0-h5.1.0.2423, QuTScloud c5.0.0.1919-c5.1.0.2497 - Path Traversal
CVSS 7.5
CVE-2023-41682
HIGH
FortiSandbox 2.4-4.4.0 - Path Traversal and Denial of Service via Crafted HTTP Requests
CVSS 8.1
CVE-2023-4990
HIGH
Espeak-ng Espeak NG < 1.52.0 - Path Traversal
CVSS 8.3
CVE-2023-41373
CRITICAL
BIG-IP Configuration Utility - Path Traversal
CVSS 9.9
CVE-2023-42796
HIGH
CP-8031 and CP-8050 Firmware < 05.11 - Authenticated Path Traversal via /sicweb-ajax/tmproot/ Endpoint
CVSS 7.5
CVE-2023-45352
HIGH
Atos Unify OpenScape Common Management Portal V10 < R4.17.0/R5.1.0 - Path Traversal & Arbitrary File Write
CVSS 8.8
CVE-2023-36123
HIGH
Hex-Dragon Plain Craft Launcher 2 <Alpha 1.3.9 - Path Traversal
CVSS 7.8
CVE-2023-23366
HIGH
Music Station 5.3.0-5.3.21 - Authenticated Path Traversal
CVSS 7.7
CVE-2023-23365
HIGH
QNAP Music Station 5.3.0-5.3.21 - Authenticated Path Traversal
CVSS 7.7
CVE-2023-43070
MEDIUM
Dell SmartFabric Storage Software <1.4 - Path Traversal
CVSS 6.3
CVE-2023-5399
CRITICAL
Schneider Electric SpaceLogic C-Bus Toolkit < 1.16.4 - Path Traversal via File Command
CVSS 9.8
CVE-2023-3701
CRITICAL
Aqua Drive 2.4 - Authenticated Path Traversal
CVSS 9.9
CVE-2023-3512
HIGH
Setelsa Security's ConacWin CB <3.8.2.2 - Path Traversal
CVSS 7.5
CVE-2023-26152
HIGH
static-server < 3.0.0 - Path Traversal via validPath Function
CVSS 7.5
CVE-2023-43627
MEDIUM
FurunoSystems ACERA 1310 and 1320 Firmware < 01.26 - Authenticated Path Traversal
CVSS 5.7
CVE-2023-5327
LOW
SATO CL4NX-J Plus 1.13.2-u455_r2 - Path Traversal via /rest/dir/ full Parameter
CVSS 3.5
CVE-2023-5257
LOW
WhiteHSBG JNDIExploit 1.4 - Path Traversal in HTTPServer handleFileRequest
CVSS 3.5
CVE-2023-43662
HIGH
ShokoServer < 4.2.2 - Unauthenticated Arbitrary File Read via Image API Endpoint
CVSS 8.6
CVE-2023-43044
MEDIUM
IBM License Metric Tool 9.2 - Path Traversal
CVSS 5.3
CVE-2023-40026
MEDIUM
Argo CD < 2.3.0 - Unauthenticated Path Traversal and Information Disclosure via Helm Chart Path Prediction
CVSS 5.0
CVE-2023-44172
CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_weixin.php
CVSS 9.8
Details
Vulnerabilities
9,205
Exploit Likelihood
High