CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,220 vulnerabilities with CWE-22
CVE-2022-33897 CRITICAL
Robustel R1510 <3.1.16 - Path Traversal
CVSS 9.1
CVE-2022-41780 MEDIUM
F5OS-A/F5OS-C <1.1.0/<1.4.0 - Path Traversal
CVSS 5.5
CVE-2022-42188 HIGH
Lavalite 9.0.0 - Path Traversal via XSRF-TOKEN Cookie
CVSS 7.5
CVE-2022-39058 HIGH
RAVA Certificate Validation System - Unauthenticated Path Traversal
CVSS 7.5
CVE-2022-22245 MEDIUM
Juniper Networks Junos OS <19.1R3-S9, <19.2 - Path Traversal
CVSS 4.3
CVE-2022-3060 HIGH
GitLab CE/EE <12.7 - Info Disclosure
CVSS 7.3
CVE-2022-23770 HIGH
wisa smart_wing_cms < 19051 - Remote Command Execution via API Constructor Parameter
CVSS 8.8
CVE-2022-22128 CRITICAL
Tableau Server Administration Agent - Path Traversal
CVSS 9.8
CVE-2022-38424 HIGH
Adobe ColdFusion <Update 14 - Path Traversal
CVSS 7.2
CVE-2022-38423 MEDIUM
Adobe ColdFusion <Update 14 - Path Traversal
CVSS 4.9
CVE-2022-38422 HIGH
Adobe ColdFusion <Update 14 - Path Traversal
CVSS 7.5
CVE-2022-38421 HIGH
Adobe ColdFusion <Update 14 - Path Traversal
CVSS 7.2
CVE-2022-38418 CRITICAL
Adobe ColdFusion <Update 14 - Path Traversal
CVSS 9.8
CVE-2022-33937 HIGH
Dell GeoDrive 1.0-2.2 - Path Traversal
CVSS 7.1
CVE-2022-39802 HIGH
SAP Manufacturing Execution 15.1-15.3 - Path Traversal via File Path Request Parameter
CVSS 7.5
CVE-2022-39296 HIGH
melisplatform/melis-asset-manager < 5.0.1 - Unauthenticated Path Traversal and Arbitrary File Read
CVSS 8.6
CVE-2022-34430 HIGH
Dell Hybrid Client >=1.5 <1.8 - Path Traversal via Zip Bomb in UI
CVSS 7.1
CVE-2022-34426 HIGH
Dell Container Storage Modules 1.2 - Path Traversal & OS Command Injection
CVSS 8.8
CVE-2022-2554 MEDIUM
Enable Media Replace <4.0.0 - Path Traversal
CVSS 4.9
CVE-2022-39858 HIGH
Samsung FactoryCamera < 3.5.51 - Path Traversal and Arbitrary File Write via AtBroadcastReceiver
CVSS 7.3
CVE-2022-3389 HIGH
ikus060/rdiffweb <2.4.10 - Path Traversal
CVSS 7.5
CVE-2022-42308 CRITICAL
Veritas NetBackup < 8.2 - Path Traversal and Arbitrary File Deletion via pbx_exchange Registration
CVSS 9.0
CVE-2022-42305 MEDIUM
Veritas NetBackup < 10.0.0.1 - Path Traversal via DiscoveryService
CVSS 5.3
CVE-2022-40123 MEDIUM
mojoPortal v2.7 - Authenticated Path Traversal via 'f' Parameter in CssEditor.aspx
CVSS 6.5
CVE-2022-34429 MEDIUM
Dell Hybrid Client - Path Traversal via Zip Slip in UI
CVSS 6.5
Details
Vulnerabilities 9,220
Exploit Likelihood High