CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-37700
HIGH
Zentao Demo15 - Directory Traversal via getconfig Mode Parameter
CVSS 7.5
CVE-2022-39210
LOW
Nextcloud Android < 3.21.0 - Path Traversal
CVSS 3.2
CVE-2022-39001
HIGH
Number Identification Module - Path Traversal
CVSS 7.5
CVE-2022-2863
MEDIUM
WordPress Plugin <0.9.76 - Path Traversal
CVSS 4.9
CVE-2022-34002
MEDIUM
PDS Vista 7 < 7.1.7.2 - Authenticated Local File Inclusion via Document Parameter
CVSS 6.5
CVE-2022-39215
HIGH
tauri < 1.0.6 - Directory Traversal via Symbolic Link in readDir
CVSS 8.3
CVE-2022-1798
HIGH
kubevirt 0.20.0-0.55.1 - Path Traversal
CVSS 8.7
CVE-2022-40734
MEDIUM
UniSharp Laravel Filemanager < 2.6.4 - Path Traversal via Download Endpoint
CVSS 6.5
CVE-2022-38301
HIGH
Onedev v7.4.14 - Path Traversal via Crafted JAR File Upload
CVSS 8.8
CVE-2022-36113
MEDIUM
Cargo < 0.65.0 - Arbitrary File Corruption via .cargo-ok Symlink Extraction
CVSS 4.6
CVE-2022-37703
LOW
Amanda 3.5.1 - Directory Existence Disclosure via calcsize SUID Binary
CVSS 3.3
CVE-2022-20395
HIGH
Android -11,12,12L,13 - Path Traversal
CVSS 7.8
CVE-2022-32190
HIGH
GO - Path Traversal
CVSS 7.5
CVE-2022-26049
MEDIUM
com.diffplug.gradle:goomph <3.37.2 - Code Injection
CVSS 5.3
CVE-2022-38638
CRITICAL
Casdoor < 1.103.1 - Arbitrary File Write via FullFilePath Parameter
CVSS 9.1
CVE-2022-38614
HIGH
SmartVista Cardgen <3.28.0 - Path Traversal
CVSS 7.5
CVE-2022-38613
MEDIUM
SmartVista Cardgen <3.28.0 - Path Traversal
CVSS 6.5
CVE-2022-28741
HIGH
aEnrich a+HRD 5.0-5.4.1125v112 - Local File Inclusion via Missing Input Validation
CVSS 8.1
CVE-2022-37299
MEDIUM
Shirne CMS 1.2.0 - Path Traversal via UEditor Controller
CVSS 6.5
CVE-2022-36850
MEDIUM
Android CallBGProvider - Path Traversal and Arbitrary File Write
CVSS 4.0
CVE-2022-38258
HIGH
D-Link DIR-819 Firmware 1.06 - Local File Inclusion and Denial of Service via getpage Parameter
CVSS 8.1
CVE-2022-36081
HIGH
wikmd < 1.7.1 - Path Traversal via /list Endpoint
CVSS 7.5
CVE-2022-36065
HIGH
growthbook < 1.6.0 - Unauthenticated Path Traversal and Remote Code Execution via File Upload
CVSS 7.5
CVE-2022-2945
MEDIUM
Ajax Load More < 5.5.3 - Authenticated Path Traversal via 'type' Parameter
CVSS 4.9
CVE-2022-2943
MEDIUM
Ajax Load More < 5.5.4 - Authenticated Arbitrary File Read via alm_repeaters_export()
CVSS 4.9
Details
Vulnerabilities
9,220
Exploit Likelihood
High