CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-29967
HIGH
Glewlwyd < 2.6.2 - Path Traversal in static_compressed_inmemory_website_callback.c
CVSS 7.5
CVE-2022-24900
CRITICAL
Piano LED Visualizer < 1.3 - Path Traversal via os.path.join
CVSS 9.9
CVE-2022-29081
CRITICAL
Zoho ManageEngine <4302, <12007, <5401 - Auth Bypass
CVSS 9.8
CVE-2022-28527
HIGH
dhcms v20170919 - Arbitrary Folder Deletion via Admin Backup Endpoint
CVSS 8.1
CVE-2022-28523
HIGH
HongCMS 3.0.0 - Unauthenticated Arbitrary File Deletion via Admin Template AJAX Endpoint
CVSS 8.1
CVE-2022-28059
HIGH
verydows 2.0 - Arbitrary File Deletion via database_controller.php
CVSS 8.1
CVE-2022-28058
HIGH
verydows 2.0 - Arbitrary File Deletion via file_controller.php
CVSS 8.1
CVE-2022-29806
CRITICAL
ZoneMinder < 1.36.13 - Remote Code Execution via Invalid Language Setting
CVSS 9.8
CVE-2022-23457
HIGH
OWASP Enterprise Security API < 2.3.0.0 - Path Traversal via Validator.getValidDirectoryPath
CVSS 7.5
CVE-2022-1392
HIGH
Videos sync PDF WordPress plugin < 1.7.4 - Local File Inclusion via Unvalidated p Parameter
CVSS 7.5
CVE-2022-1391
CRITICAL
Cab fare calculator WordPress plugin < 1.0.4 - Local File Inclusion via Controller Parameter
CVSS 9.8
CVE-2022-1390
CRITICAL
Admin Word Count Column < 2.2 - Unauthenticated Path Traversal and Remote Code Execution via Null Byte Technique
CVSS 9.8
CVE-2022-24424
HIGH
Dell EMC AppSync <4.3 - Path Traversal
CVSS 7.5
CVE-2022-28444
HIGH
UCMS v1.6 - Path Traversal and Arbitrary File Read
CVSS 7.5
CVE-2022-20790
MEDIUM
Cisco Unified Communications Manager - Info Disclosure
CVSS 6.5
CVE-2022-27925
HIGH
KEV
Zip Path Traversal in Zimbra (mboximport) (CVE-2022-27925)
CVSS 7.2
CVE-2022-1119
HIGH
Simple File List <= 3.2.7 - Unauthenticated Arbitrary File Download via eeFile Parameter
CVSS 7.5
CVE-2022-29464
CRITICAL
KEV
WSO2 Arbitrary File Upload to RCE
CVSS 9.8
CVE-2022-29281
HIGH
Notable <1.9.0-beta.8 - Code Injection
CVSS 8.8
CVE-2022-24851
HIGH
LDAP Account Manager < 7.9.1 - Authenticated Stored Cross-Site Scripting and Path Traversal via Profile Editor
CVSS 8.1
CVE-2022-27043
HIGH
Yearning 2.3.1-2.3.2 Interstellar GA and 2.3.4-2.3.6 Neptune - Path Traversal
CVSS 7.5
CVE-2022-20727
MEDIUM
Cisco IOx Application Hosting - Path Traversal
CVSS 5.5
CVE-2022-20726
MEDIUM
Cisco IOx Application Hosting - Improper Error Handling
CVSS 5.5
CVE-2022-20725
MEDIUM
Cisco IOx Application Hosting - Path Traversal and Cross-Site Scripting
CVSS 5.5
CVE-2022-20724
MEDIUM
Cisco CGR1000 Compute Module - Path Traversal
CVSS 5.5
Details
Vulnerabilities
9,220
Exploit Likelihood
High