CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,136 vulnerabilities with CWE-22
CVE-2025-43190 MEDIUM
iPadOS < 26.0 - Path Traversal via Directory Path Handling
CVSS 5.5
CVE-2025-59056 HIGH
FreePBX 15.0-15.0.37 - Path Traversal via Module Uninstall Function
CVSS 7.5
CVE-2025-10472 MEDIUM
MoneyPrinterTurbo <= 1.2.6 - Path Traversal via file_path Argument
CVSS 5.3
CVE-2025-49089 MEDIUM
MoneyPrinterTurbo 1.2.6 - Path Traversal via Download API
CVSS 6.3
CVE-2025-10176 HIGH
The Hack Repair Guy's Plugin Archiver <2.0.4 - Privilege Escalation
CVSS 7.2
CVE-2025-10273 LOW
10oa 1.0 - Path Traversal via File Parameter in /view/file.aspx
CVSS 3.5
CVE-2025-58321 CRITICAL
Delta Electronics DIALink - Path Traversal
CVSS 10.0
CVE-2025-58320 HIGH
Delta Electronics DIALink - Path Traversal
CVSS 7.3
CVE-2025-9918 HIGH
Google SecOps SOAR Server <6.3.54.0 - Path Traversal
CVE-2025-9693 HIGH
User Meta - User Profile Builder <3.1.2 - Privilege Escalation
CVSS 8.0
CVE-2025-10245 MEDIUM
Display Painéis TGA <7.1.41 - Path Traversal
CVSS 4.3
CVE-2025-10236 MEDIUM
binary-husky gpt_academic < 3.91 - Path Traversal via LaTeX File Handler
CVSS 4.3
CVE-2025-10233 MEDIUM
kodbox 1.61 - Path Traversal via fileGet/fileSave Function
CVSS 6.3
CVE-2025-10232 MEDIUM
299ko < 2.0.0 - Path Traversal via FileManagerAPIController getSentDir/delete Function
CVSS 5.4
CVE-2025-59049 HIGH
Mockoon < 9.2.0 - Path Traversal and Local File Inclusion via Static File Serving Configuration
CVSS 7.5
CVE-2025-29592 MEDIUM
Aaluoxiang OA System - Path Traversal
CVSS 5.6
CVE-2025-41714 HIGH
Welotec SmartEMS Web Application <= v3.3.6 - Path Traversal
CVSS 8.8
CVE-2025-34176 MEDIUM
pfSense < 2.8.0 - Authenticated Path Traversal in Suricata IP Reputation Check
CVSS 4.3
CVE-2025-23343 HIGH
NVIDIA NVDebug < 1.7.0 - Path Traversal and Arbitrary File Write
CVSS 7.6
CVE-2025-47415 MEDIUM
CRESTRON TOUCHSCREENS x70 - Path Traversal
CVE-2025-34173 MEDIUM
pfSense < 2.8.0 - Authenticated Path Traversal in Snort IP Reputation Check
CVSS 4.3
CVE-2025-54261 CRITICAL
ColdFusion 2025.3 2023.15 2021.21 and earlier - Path Traversal
CVSS 10.0
CVE-2025-58755 HIGH
MONAI < 1.5.0 - Path Traversal via Zip File Extraction
CVSS 8.8
CVE-2025-58751 MEDIUM
Vite <7.1.5, <7.0.7, <6.3.6, <5.4.20 - Auth Bypass
CVSS 5.3
CVE-2025-5993 CRITICAL
ITCube CRM <2025.2 - Path Traversal
Details
Vulnerabilities 9,136
Exploit Likelihood High