CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,220 vulnerabilities with CWE-22
CVE-2022-29062 MEDIUM
Fortinet FortiSOAR <7.2.1 - Path Traversal
CVSS 6.3
CVE-2022-39838 HIGH
Systematic FIX Adapter Firmware 2.4.0.25 - Path Traversal via UNC Share Pathname
CVSS 8.6
CVE-2022-34378 MEDIUM
Dell PowerScale OneFS 9.0.0-9.1.0.20, 9.2.1.13, 9.3.0.6, 9.4.0.3 - Denial of Service via Relative Path Traversal
CVSS 5.5
CVE-2022-25371 CRITICAL
Apache OFBiz < 18.12.06 - Remote Code Execution via Birt Plugin
CVSS 9.8
CVE-2022-36593 MEDIUM
kkFileView <4.0.0 - Info Disclosure
CVSS 6.5
CVE-2022-34373 HIGH
Dell Command | Integration Suite for System Center < 6.2.0 - Authenticated Arbitrary File Write
CVSS 7.3
CVE-2022-37122 HIGH
Carel pCOWeb HVAC BACnet Gateway 2.1.0 - Unauthenticated Arbitrary File Disclosure via Logdownload.cgi File Parameter
CVSS 7.5
CVE-2022-36035 HIGH
fluxcd/flux2 0.21.0-0.31.0 - Path Traversal via User-Supplied Input
CVSS 7.7
CVE-2022-34375 HIGH
Dell Container Storage Modules < 1.3.0 - Authenticated Path Traversal in goiscsi and gobrick Libraries
CVSS 8.8
CVE-2022-37681 HIGH
Hitachi HC-IP9100HD Firmware < 1.07 - Path Traversal via /ptippage.cgi GET Request
CVSS 7.5
CVE-2022-2261 HIGH
WPIDE < 3.0 - Local File Inclusion via Filename Parameter
CVSS 7.2
CVE-2022-36687 MEDIUM
Ingredients Stock Management System 1.0 - Arbitrary File Deletion via Master.php delete_img Parameter
CVSS 6.5
CVE-2022-38794 HIGH
zaver < 2020-12-15 - Path Traversal via GET /.. Substring
CVSS 7.5
CVE-2022-36168 LOW
wuzhicms 4.1.0 - Path Traversal via /coreframe/app/attachment/admin/index.php
CVSS 2.7
CVE-2022-2464 HIGH
Rockwell Automation ISaGRAF Workbench 6.0-6.6.9 - Path Traversal via Crafted Malicious Files
CVSS 7.7
CVE-2022-2463 MEDIUM
Rockwell Automation ISaGRAF Workbench 6.0-6.6.9 - Path Traversal via Malicious .7z Exchange File
CVSS 6.1
CVE-2022-32427 HIGH
PrinterLogic Windows Client < 25.0.0.688 - Authenticated Path Traversal
CVSS 8.8
CVE-2022-34836 MEDIUM
ABB Zenon < 8.20 - Path Traversal and Log Flooding
CVSS 5.9
CVE-2022-35235 MEDIUM
XplodedThemes WPide <2.6 - Info Disclosure
CVSS 4.9
CVE-2022-36261 CRITICAL
taocms 3.0.2 - Arbitrary File Deletion via Admin File Deletion Endpoint
CVSS 9.1
CVE-2022-34486 HIGH
PukiWiki 1.4.5-1.5.3 - Authenticated Path Traversal
CVSS 7.2
CVE-2022-30547 CRITICAL
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Path Traversal and Arbitrary Command Execution via unzipDirectory
CVSS 9.9
CVE-2022-2557 HIGH
Team WordPress <4.1.2 - Path Traversal
CVSS 8.8
CVE-2022-2788 LOW
Emerson Electric's Proficy Machine Edition <= 9.80 - Path Traversal via .BLZ File Upload
CVSS 3.9
CVE-2022-37422 HIGH
Payara < 4.1.2.191.36 and < 5.2022.3 - Unauthenticated Path Traversal
CVSS 7.5
Details
Vulnerabilities 9,220
Exploit Likelihood High