CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-29844
MEDIUM
Western Digital My Cloud OS 5 - Path Traversal and Arbitrary File Write via FTP Service
CVSS 6.7
CVE-2022-25882
HIGH
ONNX < 1.13.0 - Path Traversal via Tensor Proto External Data Field
CVSS 7.5
CVE-2022-21192
HIGH
serve-lite - Path Traversal via req.url
CVSS 7.5
CVE-2022-46639
HIGH
Correos Prestashop <1.7.x - Path Traversal
CVSS 7.5
CVE-2022-46959
MEDIUM
sonic < 1.0.5 - Path Traversal via /admin/backups/work-dir
CVSS 4.3
CVE-2022-47747
HIGH
uber/kraken <= 0.1.4 - Arbitrary File Read via testfs Component
CVSS 7.5
CVE-2022-43975
HIGH
GE Grid Solutions MS3000 <3.7.6.25p0-4.7p0 - Path Traversal
CVSS 7.5
CVE-2022-2893
HIGH
RONDS EPM 1.19.5 - Path Traversal via Filename Parameter
CVSS 8.2
CVE-2022-41956
MEDIUM
Autolab < 2.10.0 - Path Traversal and Arbitrary File Read via Remote Handin Feature
CVSS 6.5
CVE-2022-23532
HIGH
APOC < 4.3.0.12 - Path Traversal via apoc.export.* Procedures
CVSS 7.1
CVE-2022-45299
CRITICAL
webbrowser < 0.8.3 - Path Traversal via IpFile Argument
CVSS 9.8
CVE-2022-42136
HIGH
MailEnable < 8.66 - Authenticated Remote Code Execution via Public Folder File Upload
CVSS 8.8
CVE-2022-3693
HIGH
FileOrbis File Management System < 10.6.3 - Path Traversal
CVSS 7.5
CVE-2022-3782
CRITICAL
Keycloak - Path Traversal via Double URL Encoding
CVSS 9.1
CVE-2022-42287
MEDIUM
NVIDIA BMC < 00.19.07 - Authenticated Path Traversal and Arbitrary File Upload/Download via IPMI Handler
CVSS 6.0
CVE-2022-42282
MEDIUM
NVIDIA BMC < 00.19.07 - Authenticated Path Traversal via SPX REST API
CVSS 6.5
CVE-2022-42280
HIGH
NVIDIA BMC < 00.19.07 - Unauthenticated Path Traversal in SPX REST Auth Handler
CVSS 7.1
CVE-2022-4885
MEDIUM
sviehb jefferson <0.4 - Path Traversal
CVSS 5.0
CVE-2022-48253
CRITICAL
Nostromo < 2.1 - Path Traversal and Remote Code Execution via homedirs Option
CVSS 9.8
CVE-2022-4636
HIGH
Black Box KVM Firmware <3.4.31307 - Path Traversal
CVSS 7.5
CVE-2022-45093
HIGH
SINEC INS < V1.0 SP2 Update 1 - Authenticated Path Traversal and Arbitrary File Write via Web Based Management and SFTP
CVSS 8.5
CVE-2022-45092
CRITICAL
SINEC INS < V1.0 SP2 Update 1 - Authenticated Path Traversal and Arbitrary File Write via Web Based Management
CVSS 9.9
CVE-2022-43514
HIGH
Automation License Manager <6.0 SP9 Upd4 - Path Traversal
CVSS 7.7
CVE-2022-36928
MEDIUM
Zoom for Android < 5.13.0 - Path Traversal and Arbitrary File Write via Application Data Directory
CVSS 6.1
CVE-2022-4884
LOW
Tribe29 Checkmk <=2.0.0p32, <=2.1.0p18 - Path Traversal
CVSS 3.5
Details
Vulnerabilities
9,220
Exploit Likelihood
High