CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,223 vulnerabilities with CWE-22
CVE-2021-41281 HIGH
Synapse < 1.47.1 - Unauthenticated Path Traversal via Media Repository
CVSS 7.5
CVE-2021-24644 HIGH
Images to WebP < 1.9 - Local File Inclusion via Unsanitized Tab Parameter
CVSS 7.5
CVE-2021-37023 MEDIUM
HarmonyOS - Improper Access Control
CVSS 6.5
CVE-2021-38146 HIGH
Wipro Holmes Orchestrator <20.4.1 - Path Traversal
CVSS 7.5
CVE-2021-33491 MEDIUM
OX App Suite <7.10.5 - Path Traversal
CVSS 6.5
CVE-2021-43555 HIGH
mySCADA myDESIGNER <8.20.0 - Path Traversal
CVSS 7.3
CVE-2021-22028 CRITICAL
Greenplum < 5.28.6 - Path Traversal and Arbitrary File Write
CVSS 9.1
CVE-2021-37938 MEDIUM
Kibana 7.9.0-7.15.1 - Path Traversal via .pbf File Loading
CVSS 4.3
CVE-2021-41277 CRITICAL KEV
Metabase - Path Traversal and Local File Inclusion via Custom GeoJSON Map URL
CVSS 10.0
CVE-2021-40745 HIGH
Adobe Campaign <21.2.1 - Path Traversal
CVSS 7.5
CVE-2021-41950 CRITICAL
ResourceSpace 9.6 - Unauthenticated Path Traversal and Arbitrary File Deletion via Tiles Endpoint
CVSS 9.1
CVE-2021-43495 HIGH
AlquistManager - Path Traversal in IO/input.py
CVSS 7.5
CVE-2021-43493 HIGH
ServerManagement - Path Traversal and Credential Exposure
CVSS 7.5
CVE-2021-43492 HIGH
AlquistManager - Path Traversal
CVSS 7.5
CVE-2021-43496 HIGH
Clustering - Path Traversal
CVSS 7.5
CVE-2021-43494 HIGH
OpenCV-REST-API - Path Traversal
CVSS 7.5
CVE-2021-34422 HIGH
Keybase < 5.7.0 - Path Traversal and Remote Code Execution via Team Folder File Upload
CVSS 7.2
CVE-2021-3907 HIGH
OctoRPKI < 1.3.0 - Path Traversal and Remote Code Execution via Unsanitized URI Filename
CVSS 7.4
CVE-2021-22870 MEDIUM
GitHub Enterprise Server <3.3 - Path Traversal
CVSS 6.5
CVE-2021-42021 HIGH
Siveillance Video DLNA Server 2019 R1-2021 R1 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2021-40359 HIGH
SIMATIC BATCH - Path Traversal via File Download
CVSS 7.7
CVE-2021-40358 CRITICAL
SIMATIC PCS 7 & WinCC - Path Traversal
CVSS 9.9
CVE-2021-3924 HIGH
Grav < 1.7.24 - Path Traversal
CVSS 7.5
CVE-2021-3916 MEDIUM
BookStack < 21.10.3 - Path Traversal
CVSS 6.5
CVE-2021-21698 HIGH
Jenkins Subversion Plugin < 2.15.0 - Path Traversal via Subversion Key File Lookup
CVSS 7.5
Details
Vulnerabilities 9,223
Exploit Likelihood High