CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,221 vulnerabilities with CWE-22
CVE-2021-46902
HIGH
Meinberg LANTIME-Firmware <6.24.029 - Path Traversal
CVSS 7.2
CVE-2021-22281
MEDIUM
B&R Industrial Automation Studio 4.0-4.12 - Path Traversal
CVSS 6.3
CVE-2021-24566
HIGH
WooCommerce Currency Switcher FOX < 1.3.7 - Local File Inclusion via woocs Shortcode
CVSS 8.8
CVE-2021-42797
HIGH
AVEVA Edge < 2020 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2021-35975
MEDIUM
Systematica SMTP Adapter <2.0.1.101 - Path Traversal
CVSS 5.3
CVE-2021-22151
LOW
Kibana 7.9.0-7.13.4 - Path Traversal via .pbf File Loading
CVSS 3.1
CVE-2021-26736
MEDIUM
Zscaler Client Connector < 3.6 - Local Privilege Escalation via Path Traversal
CVSS 6.7
CVE-2021-46897
MEDIUM
Wagtail CRX CodeRed Extensions <0.22.3 - Path Traversal
CVSS 6.5
CVE-2021-28485
MEDIUM
Ericsson MSC Server BC 18A Firmware IS 3.1 - Authenticated Path Traversal via SIS Web App
CVSS 4.3
CVE-2021-35980
HIGH
Acrobat Reader DC <2021.005.20054 - Path Traversal
CVSS 7.8
CVE-2021-28644
HIGH
Adobe Acrobat and Reader DC < 21.005.20058 and < 17.011.30199 - Path Traversal and Code Execution
CVSS 7.8
CVE-2021-26504
HIGH
dgtl huemagic 3.0.0 - Path Traversal via res.sendFile API
CVSS 7.5
CVE-2021-27825
HIGH
Mercury MAC1200R Firmware - Unauthenticated Path Traversal via web-static/ URL
CVSS 7.5
CVE-2021-33353
CRITICAL
Wyomind Help Desk Magento 2 <1.3.7 - Path Traversal
CVSS 9.8
CVE-2021-36471
CRITICAL
AdminLTE 3.1.0 - Path Traversal via Index2 and Index3 URIs
CVSS 9.8
CVE-2021-37317
CRITICAL
ASUS RT-AC68U Firmware < 3.0.0.4.386.41634 - Path Traversal and Arbitrary File Write via Cloud Disk COPY/MOVE Operations
CVSS 9.1
CVE-2021-36425
MEDIUM
phpwcms < 1.9.26 - Path Traversal and Arbitrary File Deletion via FTP Takeover Unlink Method
CVSS 5.4
CVE-2021-41143
HIGH
OpenMage LTS <19.4.22-20.0.19 - RCE
CVSS 7.2
CVE-2021-37500
HIGH
Reprise License Manager < 16.0 - Path Traversal and Arbitrary File Write via Diagnostics Function
CVSS 8.1
CVE-2021-39369
MEDIUM
Philips Vue MyVue PACS through 12.2.x.x - Authenticated Path Traversal via VideoStream Function
CVSS 6.5
CVE-2021-46856
HIGH
Multi-Screen Collaboration Module - Path Traversal
CVSS 7.5
CVE-2021-45448
HIGH
Hitachi Vantara Pentaho 8.3.0.0-8.3.0.25 - Path Traversal via Analyzer Plugin Template Endpoint
CVSS 7.1
CVE-2021-40661
HIGH
IND780 Advanced Weighing Terminals <8.0.07,7.2.10 - Path Traversal
CVSS 7.5
CVE-2021-38399
HIGH
Honeywell Experion PKS - Path Traversal
CVSS 7.5
CVE-2021-22685
MEDIUM
Cassia Networks Access Controller <2.0.1 - Info Disclosure
CVSS 6.2
Details
Vulnerabilities
9,221
Exploit Likelihood
High