CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-29062
MEDIUM
Fortinet FortiSOAR <7.2.1 - Path Traversal
CVSS 6.3
CVE-2022-39838
HIGH
Systematic FIX Adapter Firmware 2.4.0.25 - Path Traversal via UNC Share Pathname
CVSS 8.6
CVE-2022-34378
MEDIUM
Dell PowerScale OneFS 9.0.0-9.1.0.20, 9.2.1.13, 9.3.0.6, 9.4.0.3 - Denial of Service via Relative Path Traversal
CVSS 5.5
CVE-2022-25371
CRITICAL
Apache OFBiz < 18.12.06 - Remote Code Execution via Birt Plugin
CVSS 9.8
CVE-2022-36593
MEDIUM
kkFileView <4.0.0 - Info Disclosure
CVSS 6.5
CVE-2022-34373
HIGH
Dell Command | Integration Suite for System Center < 6.2.0 - Authenticated Arbitrary File Write
CVSS 7.3
CVE-2022-37122
HIGH
Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Unauthenticated Arbitrary File Disclosure via Logdownload.cgi File Parameter
CVSS 7.5
CVE-2022-36035
HIGH
fluxcd/flux2 0.21.0-0.31.0 - Path Traversal via User-Supplied Input
CVSS 7.7
CVE-2022-34375
HIGH
Dell Container Storage Modules < 1.3.0 - Authenticated Path Traversal in goiscsi and gobrick Libraries
CVSS 8.8
CVE-2022-37681
HIGH
Hitachi HC-IP9100HD Firmware < 1.07 - Path Traversal via /ptippage.cgi GET Request
CVSS 7.5
CVE-2022-2261
HIGH
WPIDE < 3.0 - Local File Inclusion via Filename Parameter
CVSS 7.2
CVE-2022-36687
MEDIUM
Ingredients Stock Management System 1.0 - Arbitrary File Deletion via Master.php delete_img Parameter
CVSS 6.5
CVE-2022-38794
HIGH
zaver < 2020-12-15 - Path Traversal via GET /.. Substring
CVSS 7.5
CVE-2022-36168
LOW
wuzhicms 4.1.0 - Path Traversal via /coreframe/app/attachment/admin/index.php
CVSS 2.7
CVE-2022-2464
HIGH
Rockwell Automation ISaGRAF Workbench 6.0-6.6.9 - Path Traversal via Crafted Malicious Files
CVSS 7.7
CVE-2022-2463
MEDIUM
Rockwell Automation ISaGRAF Workbench 6.0-6.6.9 - Path Traversal via Malicious .7z Exchange File
CVSS 6.1
CVE-2022-32427
HIGH
PrinterLogic Windows Client < 25.0.0.688 - Authenticated Path Traversal
CVSS 8.8
CVE-2022-34836
MEDIUM
ABB Zenon < 8.20 - Path Traversal and Log Flooding
CVSS 5.9
CVE-2022-35235
MEDIUM
XplodedThemes WPide <2.6 - Info Disclosure
CVSS 4.9
CVE-2022-36261
CRITICAL
taocms 3.0.2 - Arbitrary File Deletion via Admin File Deletion Endpoint
CVSS 9.1
CVE-2022-34486
HIGH
PukiWiki 1.4.5-1.5.3 - Authenticated Path Traversal
CVSS 7.2
CVE-2022-30547
CRITICAL
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Path Traversal and Arbitrary Command Execution via unzipDirectory
CVSS 9.9
CVE-2022-2557
HIGH
Team WordPress <4.1.2 - Path Traversal
CVSS 8.8
CVE-2022-2788
LOW
Emerson Electric's Proficy Machine Edition <= 9.80 - Path Traversal via .BLZ File Upload
CVSS 3.9
CVE-2022-37422
HIGH
Payara < 4.1.2.191.36 and < 5.2022.3 - Unauthenticated Path Traversal
CVSS 7.5
Details
Vulnerabilities
9,220
Exploit Likelihood
High