CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,222 vulnerabilities with CWE-22
CVE-2021-40003 MEDIUM
HarmonyOS < 2.0 - Path Traversal in HwPCAssistant
CVSS 5.3
CVE-2021-40001 MEDIUM
HarmonyOS < 2.0 - Path Traversal in CaasKit Module
CVSS 5.3
CVE-2021-44351 HIGH
NavigateCMS 2.9 - Arbitrary File Read via navigate_download.php id Parameter
CVSS 7.5
CVE-2021-45452 MEDIUM
Django 2.2-2.2.25, 3.2-3.2.10, 4.0-4.0.0 - Path Traversal via Storage.save
CVSS 5.3
CVE-2021-39143 MEDIUM
Spinnaker < 1.24.7 - Path Traversal via TAR File Extraction in AppEngine Deployments
CVSS 6.6
CVE-2021-40525 CRITICAL
Apache James <3.6.1 - Path Traversal
CVSS 9.1
CVE-2021-39970 HIGH
HarmonyOS < 2.0 - Path Traversal in HwPCAssistant
CVSS 7.5
CVE-2021-37128 CRITICAL
HarmonyOS < 2.0 - Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2021-37126 HIGH
HarmonyOS < 2.0 - Path Traversal and Information Exposure
CVSS 7.5
CVE-2021-44674 MEDIUM
Opmantek Open-AudIT 4.2.0 - Authenticated Path Traversal
CVSS 6.5
CVE-2021-25021 MEDIUM
OMGF | Host Google Fonts Locally WP <4.5.12 - Path Traversal
CVSS 4.9
CVE-2021-25020 MEDIUM
CAOS | Host Google Analytics Locally <4.1.9 - Path Traversal
CVSS 4.9
CVE-2021-20134 HIGH
D-Link DIR-2640-US Firmware <= 1.11B02 - Authenticated Path Traversal and Remote Code Execution via Quagga Log File
CVSS 8.4
CVE-2021-20133 MEDIUM
D-Link DIR-2640-US Firmware <= 1.11B02 - Authenticated Path Traversal and Information Disclosure via Quagga Services
CVSS 6.1
CVE-2021-45427 CRITICAL
Emerson XWEB 300D EVO 3.0.7--3ee403 - Unauthenticated Path Traversal and Arbitrary File Deletion
CVSS 9.8
CVE-2021-45712 HIGH
rust-embed < 6.3.0 - Path Traversal in Debug Mode
CVSS 7.5
CVE-2021-20876 MEDIUM
GroupSession <5.1.1 - Info Disclosure
CVSS 6.8
CVE-2021-44548 CRITICAL
Apache Solr < 8.11.1 - Path Traversal via DataImportHandler Windows UNC Path
CVSS 9.8
CVE-2021-21909 HIGH
Garrett IC Module Firmware - Arbitrary File Deletion via Crafted Command Line Arguments
CVSS 8.1
CVE-2021-21908 MEDIUM
Garrett IC Module Firmware - Authenticated Arbitrary File Deletion via Unsanitized File Parameter
CVSS 6.5
CVE-2021-21907 MEDIUM
Garrett iC Module CMA 5.0 - Path Traversal via CMA CLI getenv Command
CVSS 4.9
CVE-2021-21904 HIGH
Garrett iC Module CMA 5.0 - Path Traversal via CMA CLI setenv Command
CVSS 7.2
CVE-2021-21896 MEDIUM
Lantronix PremierWave 2050 8.9.0.0R4 Path Traversal & File Deletion via Web Manager
CVSS 6.5
CVE-2021-21895 HIGH
Lantronix PremierWave 2050 8.9.0.0R4 Path Traversal & Arbitrary File Write via Web Manager
CVSS 7.2
CVE-2021-21894 CRITICAL
Lantronix PremierWave 2050 8.9.0.0R4 Path Traversal & Arbitrary File Write via Web Manager
CVSS 9.1
Details
Vulnerabilities 9,222
Exploit Likelihood High