CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-20850
MEDIUM
Cisco SD-WAN vBond, vManage, vSmart & IOS XE SD-WAN - Authenticated Arbitrary File Deletion via CLI
CVSS 5.5
CVE-2022-20818
HIGH
Cisco SD-WAN < 20.9 - Authenticated Privilege Escalation via CLI Command Injection
CVSS 7.8
CVE-2022-20775
HIGH
KEV
Cisco SD-WAN Software - Privilege Escalation
CVSS 7.8
CVE-2022-2922
MEDIUM
Dnnsoftware Dotnetnuke < 9.11.0 - Path Traversal
CVSS 4.9
CVE-2022-40082
HIGH
Hertz 0.3.0 - Path Traversal via normalizePath Function
CVSS 7.5
CVE-2022-39261
HIGH
Twig < 1.44.7, 2.x < 2.15.3, 3.x < 3.4.3 - Path Traversal via Namespace Bypass
CVSS 7.5
CVE-2022-28814
CRITICAL
Carlo Gavazzi UWP3.0 - Path Traversal
CVSS 9.8
CVE-2022-39034
MEDIUM
Smart eVision - Path Traversal in Report API
CVSS 6.5
CVE-2022-39033
CRITICAL
Smart eVision - Unauthenticated Path Traversal and Arbitrary File Deletion via URL Parameter
CVSS 9.8
CVE-2022-40199
LOW
EC-CUBE 3.0.0-3.0.18-p4 and 4.0.0-4.1.2 - Authenticated Path Traversal
CVSS 2.7
CVE-2022-2926
MEDIUM
Adobe Download Manager < 3.2.55 - Authenticated Path Traversal via Unvalidated Setting
CVSS 4.9
CVE-2022-41352
CRITICAL
KEV
Zimbra Collaboration <9.0 - Privilege Escalation
CVSS 9.8
CVE-2022-34026
HIGH
ICEcoder 8.1 - Path Traversal
CVSS 7.5
CVE-2022-40444
MEDIUM
ZZCMS 2022 - Full Path Disclosure via /admin/index.PHP
CVSS 5.3
CVE-2022-40443
MEDIUM
ZZCMS 2022 - Path Traversal via /one/siteinfo.php GET Request
CVSS 5.3
CVE-2022-28981
HIGH
Liferay Portal <7.4.3 - Path Traversal
CVSS 7.5
CVE-2022-29799
MEDIUM
Microsoft Windows Defender For Endpoint - Path Traversal
CVSS 5.5
CVE-2022-41231
MEDIUM
Jenkins Build-Publisher Plugin <1.22 - Privilege Escalation
CVSS 5.7
CVE-2022-2265
HIGH
Identity and Directory Management System < 2.1.25 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2022-39221
HIGH
McWebserver Minecraft Mod Path Traversal via HTTP Request
CVSS 7.5
CVE-2022-38340
CRITICAL
Safe Software FME Server <2022.0.0.2 - Path Traversal
CVSS 9.1
CVE-2022-23767
HIGH
SecureGate - Unauthenticated SQL Injection and Path Traversal via Login and File Transfer
CVSS 8.8
CVE-2022-40608
HIGH
IBM Spectrum Protect Plus 10.1.6-10.1.11 - Path Traversal via Microsoft File Systems Restore URL
CVSS 7.5
CVE-2022-40715
MEDIUM
NOKIA 1350OMS R14.2 - Authenticated Path Traversal via Logfile Parameter
CVSS 6.5
CVE-2022-40713
MEDIUM
NOKIA 1350OMS R14.2 - Authenticated Path Traversal via File Parameter
CVSS 6.5
Details
Vulnerabilities
9,220
Exploit Likelihood
High