CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,205 vulnerabilities with CWE-22
CVE-2023-44171
CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_smtp.php
CVSS 9.8
CVE-2023-44170
CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_ping.php
CVSS 9.8
CVE-2023-44169
CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_notify.php
CVSS 9.8
CVE-2023-43825
HIGH
Shihonkanri Plus <9.0.3 - Path Traversal
CVSS 7.8
CVE-2023-43216
CRITICAL
SeaCMS V12.9 - Arbitrary File Write via admin_ip.php
CVSS 9.8
CVE-2023-42819
HIGH
JumpServer 3.0.0-3.6.4 - Authenticated Path Traversal and Arbitrary File Write via Playbook File Endpoint
CVSS 8.9
CVE-2023-42657
CRITICAL
WS_FTP Server < 8.7.4 - Path Traversal and Arbitrary File Operations
CVSS 9.9
CVE-2023-42487
HIGH
soundminer < 2.01 - Path Traversal
CVSS 7.5
CVE-2023-42462
HIGH
GLPI 10.0.0-10.0.9 - Path Traversal and Arbitrary File Deletion via Document Upload Process
CVSS 7.7
CVE-2023-41888
MEDIUM
GLPI 10.0.8-10.0.9 - Path Traversal via Login Page URL
CVSS 5.3
CVE-2023-40532
MEDIUM
Welcart e-Commerce <2.8.21 - Info Disclosure
CVSS 4.3
CVE-2023-2315
HIGH
OpenCart 4.0.0.0-4.0.2.2 - Authenticated Path Traversal via Log Component
CVSS 8.1
CVE-2023-43382
HIGH
ItechYou Dreamer CMS <4.1.3 - Code Injection
CVSS 8.8
CVE-2023-43256
MEDIUM
Gladys Assistant <4.26.1 - Path Traversal
CVSS 6.5
CVE-2023-41302
HIGH
Redirection Permission Verification - Info Disclosure
CVSS 7.5
CVE-2023-39407
CRITICAL
HarmonyOS - Unauthenticated Path Traversal in Watchkit
CVSS 9.1
CVE-2023-5142
LOW
H3C GR and ER Series Firmware < 20230908 - Path Traversal via /userLogin.asp Config File Handler
CVSS 3.7
CVE-2023-38346
HIGH
Wind River VxWorks 6.9-7 - Path Traversal
CVSS 8.8
CVE-2023-42280
HIGH
mee-admin 1.5 - Path Traversal via CommonFileController Download Method
CVSS 7.5
CVE-2023-42456
LOW
sudo-rs < 0.2.1 - Path Traversal via Username with Special Characters
CVSS 3.3
CVE-2023-4760
HIGH
Eclipse RAP 3.0.0-3.25.0 - Remote Code Execution via FileUpload Path Traversal
CVSS 7.6
CVE-2023-4152
HIGH
Frauscher FDS101 < 1.4.24 - Unauthenticated Path Traversal via Crafted URL
CVSS 7.5
CVE-2023-40930
MEDIUM
Skyworth OS v3.0 - Path Traversal via Udisk Mount to /mnt/
CVSS 6.8
CVE-2023-43616
MEDIUM
schollz/croc < 9.6.5 - Path Traversal via ZIP Extraction
CVSS 5.5
CVE-2023-41599
MEDIUM
jfinalcms 5.0.0 - Path Traversal via DownController
CVSS 5.3
Details
Vulnerabilities
9,205
Exploit Likelihood
High