CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,141 vulnerabilities with CWE-22
CVE-2025-6020
HIGH
Red Hat Enterprise Linux - Privilege Escalation via pam_namespace Symlink Race Condition
CVSS 7.8
CVE-2025-6167
MEDIUM
python-a2a < 0.5.6 - Path Traversal in create_workflow Function
CVSS 5.5
CVE-2025-6166
LOW
agent-zero < 0.8.4.1 - Path Traversal in image_get Function
CVSS 3.5
CVE-2025-6152
MEDIUM
Steel Browser <= 0.1.3 - Path Traversal via File Upload Filename
CVSS 6.3
CVE-2025-32799
CRITICAL
conda-build < 25.4.0 - Path Traversal via Tar Entry Processing
CVSS 9.8
CVE-2025-3594
CRITICAL
Liferay DXP 7.0.0-7.4.3.4 - Path Traversal & Arbitrary File Write via Xuggler
CVSS 9.8
CVE-2025-4748
MEDIUM
Erlang/OTP 17.0-28.0.1, 27.3.4.1, 26.2.5.13 - Path Traversal in zip.erl
CVE-2025-6109
MEDIUM
Javahongxi Whatsmars 2021.4.0 - Path Traversal
CVSS 4.3
CVE-2025-6108
MEDIUM
hansonwang99 Spring-Boot-In-Action <807fd37643aa774b94fd004cc3adbd2...
CVSS 6.3
CVE-2025-5964
MEDIUM
M-Files Server < 24.8.13981.16 and 25.3.14681.7-25.6.14925.0 - Authenticated Path Traversal via API Endpoint
CVSS 6.5
CVE-2025-6070
MEDIUM
Restrict File Access <1.1.2 - Path Traversal
CVSS 6.5
CVE-2025-6065
CRITICAL
WordPress Image Resizer On The Fly <2.0 - Path Traversal
CVSS 9.1
CVE-2025-4187
MEDIUM
UserPro - Community and User Profile WordPress Plugin <5.1.10 - Pat...
CVSS 5.9
CVE-2025-28384
CRITICAL
OpenC3 COSMOS < 6.1.0 - Path Traversal via Script API Endpoint
CVSS 9.1
CVE-2025-28382
HIGH
OpenC3 COSMOS < 6.1.0 - Path Traversal via openc3-api/tables Endpoint
CVSS 7.5
CVE-2025-46096
MEDIUM
solon 3.1.2 - Path Traversal and Cross-Site Scripting via solon-faas-luffy Component
CVSS 6.1
CVE-2025-46783
CRITICAL
RICOH Streamline NX V3 PC Client <3.242.0 - Path Traversal
CVSS 9.8
CVE-2025-22241
MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Path Traversal in VirtKey Class
CVSS 5.6
CVE-2025-22240
MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Arbitrary File Deletion via GitFS find_file Method
CVSS 6.3
CVE-2025-22238
MEDIUM
Salt 3006.0rc1-3006.11 and 3007.0-3007.3 - Path Traversal and Arbitrary File Write in Minion File Cache
CVSS 4.2
CVE-2025-4613
HIGH
Google Web Designer <16.3.0.0407 - Path Traversal
CVSS 8.8
CVE-2025-40592
MEDIUM
Mendix Studio Pro <10.23.0, <10.12.17, <10.18.7, <10.6.24, <11.0.0,...
CVSS 6.1
CVE-2025-47176
HIGH
Microsoft 365 Apps and Office LTSC - Path Traversal and Local Code Execution via Outlook Path Handling
CVSS 7.8
CVE-2025-37100
HIGH
HPE Aruba Networking Private 5G Core - Info Disclosure
CVSS 7.7
CVE-2025-5741
MEDIUM
Charging Station < - Path Traversal
CVSS 4.9
Details
Vulnerabilities
9,141
Exploit Likelihood
High