CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,127 vulnerabilities with CWE-22
CVE-2025-48636
HIGH
BugreportContentProvider - Path Traversal
CVSS 8.4
CVE-2025-48567
HIGH
Android - Path Traversal via Unicode Normalization Bypass
CVSS 7.8
CVE-2025-50857
CRITICAL
ZenTaoPMS 18.11-21.6.beta - Path Traversal
CVSS 9.8
CVE-2025-11563
MEDIUM
wcurl 2024-12-08-2025-11-09 - Path Traversal via Percent-Encoded Slashes
CVSS 4.6
CVE-2025-15589
LOW
MuYuCMS 2.7 - Path Traversal via Template Management Page
CVSS 3.8
CVE-2025-69380
HIGH
Upload Files Anywhere <=2.8 - Path Traversal
CVSS 7.5
CVE-2025-69379
HIGH
Upload Files Anywhere <=2.8 - Path Traversal
CVSS 8.6
CVE-2025-69377
HIGH
User Extra Fields <=17.0 - Path Traversal
CVSS 7.7
CVE-2025-69376
HIGH
User Extra Fields <=17.0 - Path Traversal
CVSS 8.6
CVE-2025-68862
HIGH
Woo File Dropzone <=1.1.7 - Path Traversal
CVSS 7.7
CVE-2025-68002
MEDIUM
Open User Map <=1.4.16 - Path Traversal
CVSS 6.5
CVE-2025-59819
MEDIUM
Zenitel AlphaCom XE Audio Server - Authenticated Arbitrary File Read via Filepath Parameter
CVSS 6.5
CVE-2025-8054
HIGH
OpenText XM Fax 24.2 - Path Traversal
CVSS 7.5
CVE-2025-36598
MEDIUM
Dell Avamar <19.12 - Path Traversal
CVSS 6.5
CVE-2025-36597
MEDIUM
Dell Avamar <19.12 - Path Traversal
CVSS 4.7
CVE-2025-12062
HIGH
WP Maps Plugin <4.8.6 - Local File Inclusion
CVSS 8.8
CVE-2025-13681
MEDIUM
BFG Tools Extension Zipper <1.0.7 - Path Traversal
CVSS 4.9
CVE-2025-69770
CRITICAL
MojoPortal CMS <2.9.0.1 - Command Injection
CVSS 10.0
CVE-2025-15577
HIGH
Valmet DNA Web Tools <C2022 - Info Disclosure
CVSS 7.5
CVE-2025-64074
MEDIUM
Shenzhen Zhibotong Electronics ZBT WE2001 <23.09.27 - Path Traversal
CVSS 5.3
CVE-2025-43537
MEDIUM
iPadOS < 18.7.5 - Path Traversal via Malicious Backup File
CVSS 5.5
CVE-2025-43417
MEDIUM
macOS Sonoma <14.8.4 - Info Disclosure
CVSS 5.5
CVE-2025-70084
HIGH
OpenSatKit 2.2.1 - Path Traversal via FileUtil_GetFileInfo Function
CVSS 7.5
CVE-2025-69874
CRITICAL
nanotar <= 0.2.0 - Path Traversal and Arbitrary File Write via Crafted Tar Archive
CVSS 9.8
CVE-2025-64075
CRITICAL
Shenzhen Zhibotong Electronics ZBT WE2001 <23.09.27 - Path Traversal
CVSS 10.0
Details
Vulnerabilities
9,127
Exploit Likelihood
High