CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,223 vulnerabilities with CWE-22
CVE-2021-21894 CRITICAL
Lantronix PremierWave 2050 8.9.0.0R4 Path Traversal & Arbitrary File Write via Web Manager
CVSS 9.1
CVE-2021-21886 MEDIUM
Lantronix PremierWave 2050 Firmware 8.9.0.0R4 - Authenticated Path Traversal via Web Manager FSBrowsePage
CVSS 4.3
CVE-2021-21885 HIGH
Lantronix PremierWave 2050 Firmware 8.9.0.0R4 - Authenticated Path Traversal via Web Manager FsMove
CVSS 7.2
CVE-2021-21880 HIGH
Lantronix PremierWave 2050 Firmware 8.9.0.0R4 - Authenticated Path Traversal via Web Manager FsCopyFile
CVSS 7.2
CVE-2021-21879 HIGH
Lantronix PremierWave 2050 8.9.0.0R4 - Authenticated Path Traversal and Arbitrary File Write via Web Manager File Upload
CVSS 8.8
CVE-2021-45418 HIGH
Starcharge Titan 180 Premium <1.3.0.0.6 & Nova 360 Cabinet <1.3.0.0.7b102 Path Traversal
CVSS 8.8
CVE-2021-44162 HIGH
Chinasea QB Smart Service Robot - Path Traversal
CVSS 7.5
CVE-2021-23797 HIGH
http-server-node - Path Traversal via --path-as-is
CVSS 7.5
CVE-2021-43840 MEDIUM
message_bus <3.3.7 - Path Traversal
CVSS 4.4
CVE-2021-32498 HIGH
SICK SOPAS ET < 4.8.0 - Path Traversal and Arbitrary Executable Execution via Emulator Pathname
CVSS 8.6
CVE-2021-3960 HIGH
Bitdefender GravityZone < 3.3.8.272 - Remote Code Execution via UpdateServer Path Traversal
CVSS 7.1
CVE-2021-43836 HIGH
Sulu <1.6.44-2.4.0 - Info Disclosure
CVSS 8.5
CVE-2021-43831 HIGH
gradio < 2.5.0 - Unauthenticated Path Traversal
CVSS 7.7
CVE-2021-45043 HIGH
HD-Network Real-time Monitoring System 2.0 - Path Traversal via Language Parameter
CVSS 7.5
CVE-2021-44232 HIGH
SAF-T Framework - Path Traversal in Transaction SAFTN_G
CVSS 7.7
CVE-2021-39312 HIGH
True Ranker <= 2.2.2 - Unauthenticated Arbitrary File Read via src Parameter
CVSS 7.5
CVE-2021-45015 CRITICAL
taocms 3.0.2 - Arbitrary File Deletion via file.php
CVSS 9.1
CVE-2021-42022 MEDIUM
SIMATIC eaSie PCS 7 Skill Package < V21.00 SP3 - Path Traversal via File Download Function
CVSS 6.5
CVE-2021-41547 HIGH
Teamcenter Active Workspace < 4.3.11, < 5.0.10, < 5.1.6, < 5.2.3 - Path Traversal & RCE via Unsafe Unzipping
CVSS 7.2
CVE-2021-44965 HIGH
PHPGURUKUL Employee Record Management System 1.2 - Path Traversal in Admin Includes Directory
CVSS 7.5
CVE-2021-24970 HIGH
All-in-One Video Gallery <2.5.0 - Code Injection
CVSS 7.2
CVE-2021-40858 MEDIUM
Auerswald COMpact 5500R <8.2B - Info Disclosure
CVSS 4.9
CVE-2021-41242 HIGH
OpenOlat <15.5.12-16.0.5 - Path Traversal
CVSS 8.1
CVE-2021-43815 MEDIUM
Grafana <8.3.2, <7.5.12 - Path Traversal
CVSS 4.3
CVE-2021-43813 MEDIUM
Grafana <8.3.2, <7.5.12 - Path Traversal
CVSS 4.3
Details
Vulnerabilities 9,223
Exploit Likelihood High