CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-20962
LOW
Cisco Identity Services Engine - Authenticated Path Traversal and Arbitrary File Write via Absolute Path Sequences
CVSS 3.8
CVE-2022-41670
HIGH
SGIUtility <V3.3 Hotfix 1 - Path Traversal
CVSS 7.0
CVE-2022-41667
HIGH
EcoStruxure Operator Terminal Expert <V3.3 Hotfix 1 - Path Traversal
CVSS 7.0
CVE-2022-43451
HIGH
OpenHarmony <v3.1.2 - Path Traversal
CVSS 8.4
CVE-2022-32287
HIGH
Apache UIMA < 3.3.0 - Path Traversal via ZIP Entry in PEAR File
CVSS 7.5
CVE-2022-32938
MEDIUM
iPadOS < 16.0 - Path Traversal via Shortcut Path Handling
CVSS 5.3
CVE-2022-34662
MEDIUM
Apache DolphinScheduler < 3.0.0 - Authenticated Path Traversal via Resource Center
CVSS 6.5
CVE-2022-41772
CRITICAL
Delta Electronics InfraSuite Device Master <0.00.01a - Path Traversal
CVSS 9.8
CVE-2022-41657
CRITICAL
Delta Electronics InfraSuite Device Master <00.00.01a - Code Injection
CVSS 9.8
CVE-2022-40742
MEDIUM
Mail SQR Expert - Unauthenticated Local File Inclusion via .asp File Extension
CVSS 6.5
CVE-2022-39023
MEDIUM
U-Office Force < 20.50.7821d - Authenticated Path Traversal via Download Function
CVSS 6.5
CVE-2022-39022
MEDIUM
U-Office Force < 20.50.7821d - Authenticated Path Traversal via Download Function
CVSS 6.5
CVE-2022-39367
HIGH
QTIWorks < 1.0-beta15 - Path Traversal via ZIP File Extraction
CVSS 8.6
CVE-2022-26884
MEDIUM
Apache DolphinScheduler <2.0.6 - Info Disclosure
CVSS 6.5
CVE-2022-3387
MEDIUM
Advantech R-SeeNet <2.4.19 - Path Traversal
CVSS 6.5
CVE-2022-0072
MEDIUM
OpenLiteSpeed 1.5.11-1.5.12 1.6.5-1.6.20.1 <1.7.16.1 - Path Traversal
CVSS 5.8
CVE-2022-20955
MEDIUM
Cisco TelePresence Collaboration Endpoint and RoomOS - Path Traversal and Arbitrary File Write
CVSS 5.5
CVE-2022-20954
MEDIUM
Cisco TelePresence Collaboration Endpoint < 10.19.1 and RoomOS - Path Traversal and Arbitrary File Write
CVSS 5.5
CVE-2022-20953
MEDIUM
Cisco TelePresence Collaboration Endpoint < 10.19.1 and RoomOS - Path Traversal
CVSS 5.5
CVE-2022-20822
HIGH
Cisco Identity Services Engine - Authenticated Path Traversal and Arbitrary File Deletion via Web Interface
CVSS 7.1
CVE-2022-20811
MEDIUM
Cisco TelePresence 9.0.0.0-9.15.12.9 & RoomOS <10.15.1 - Path Traversal & Arbitrary File Write
CVSS 5.5
CVE-2022-20776
MEDIUM
Cisco TelePresence CE/RoomOS - Path Traversal
CVSS 5.5
CVE-2022-43748
MEDIUM
Synology Presto File Server <2.1.2-1601 - Path Traversal
CVSS 5.8
CVE-2022-39345
CRITICAL
gin-vue-admin < 2.5.4 - Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2022-38196
MEDIUM
Esri ArcGIS Server <10.9.1 - Path Traversal
CVSS 6.5
Details
Vulnerabilities
9,220
Exploit Likelihood
High