CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,233 vulnerabilities with CWE-22
CVE-2020-21862
HIGH
DuxCMS 2.1 - Path Traversal and Arbitrary File Deletion via AdminBackup Endpoint
CVSS 8.1
CVE-2020-19902
CRITICAL
wcms 0.3.2 - Path Traversal via wex/cssjs.php Parameter
CVSS 9.8
CVE-2020-36728
MEDIUM
Adning Advertising <1.5.5 - Path Traversal
CVSS 6.5
CVE-2020-20012
CRITICAL
WebPlus Pro v1.4.7.8.4-01 - Path Traversal
CVSS 9.8
CVE-2020-13377
HIGH
Loadbalancer.org Enterprise VA MAX <8.3.8 - Path Traversal
CVSS 8.1
CVE-2020-19678
HIGH
pfSense Suricata Package 1.0.1 - Directory Traversal via suricata_logs_browser.php file Parameter
CVSS 7.5
CVE-2020-19279
CRITICAL
B3log Wide - Directory Traversal via Symbolic Links
CVSS 9.8
CVE-2020-5001
MEDIUM
IBM Financial Transaction Manager 3.2.0-3.2.7 - Path Traversal via URL Request
CVSS 4.3
CVE-2020-18331
CRITICAL
ChinaMobile PLC Wireless Router - Path Traversal
CVSS 9.1
CVE-2020-18330
CRITICAL
ChinaMobile PLC Wireless Router <W2000EN-01 - Info Disclosure
CVSS 9.1
CVE-2020-36651
MEDIUM
Youngerheart nodeserver - Path Traversal
CVSS 5.5
CVE-2020-36647
MEDIUM
YunoHost-Apps transmission_ynh - Path Traversal
CVSS 5.5
CVE-2020-36639
MEDIUM
AlliedModders AMX Mod X < 2020-05-28 - Path Traversal via amx_votemap Argument
CVSS 4.3
CVE-2020-36566
CRITICAL
tar-utils - Path Traversal via Relative File Paths
CVSS 9.1
CVE-2020-36561
CRITICAL
unzip < 1.0.3-0.20200308084313-2adbaa4891b9 - Path Traversal via Archive Extraction
CVSS 9.1
CVE-2020-36560
CRITICAL
go-unzip < 1.0.0 and artdarek/go-unzip < 2.0.0 - Path Traversal via Archive Extraction
CVSS 9.1
CVE-2020-36559
HIGH
aah < 0.12.4 - Path Traversal via HTTPEngine.Handle
CVSS 7.5
CVE-2020-36629
MEDIUM
httpster < 1.1.0 - Path Traversal via fs.realpathSync
CVSS 5.5
CVE-2020-36628
MEDIUM
Calsign APDE <0.5.2-pre2-alpha - Path Traversal
CVSS 5.5
CVE-2020-24855
MEDIUM
easywebpack-cli < 4.5.2 - Path Traversal via Crafted GET Request
CVSS 5.3
CVE-2020-36565
MEDIUM
Labstack Echo <= 4.2.0 - Path Traversal
CVSS 5.3
CVE-2020-12508
HIGH
s::can moni::tools <4.2 - Path Traversal
CVSS 7.5
CVE-2020-12509
HIGH
s::can moni::tools <4.2 - Path Traversal
CVSS 7.5
CVE-2020-21642
CRITICAL
ManageEngine Analytics Plus < 4350 - Remote Code Execution via ZDBQAREFSUBDIR Path Traversal
CVSS 9.8
CVE-2020-21365
HIGH
wkhtmltopdf <= 0.12.5 - Path Traversal via Crafted HTML File
CVSS 7.5
Details
Vulnerabilities
9,233
Exploit Likelihood
High