CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,142 vulnerabilities with CWE-22
CVE-2025-41428
MEDIUM
TimeWorks 10.0-10.3 - Unauthenticated Path Traversal
CVSS 5.3
CVE-2025-48387
HIGH
tar-fs <3.0.9, <2.1.3, <1.16.5 - Path Traversal
CVE-2025-27956
HIGH
WebLaudos 24.2 (04) - Path Traversal via id Parameter
CVSS 7.5
CVE-2025-48940
HIGH
MyBB < 1.8.39 - Local File Inclusion via Upgrade Component Parameter
CVSS 7.2
CVE-2025-37095
CRITICAL
HPE StoreOnce System < 4.3.11 - Path Traversal
CVSS 9.8
CVE-2025-37094
MEDIUM
HPE StoreOnce System < 4.3.11 - Path Traversal and Arbitrary File Deletion
CVSS 5.5
CVE-2025-48957
HIGH
AstrBot 3.4.4-3.5.12 - Path Traversal and Information Disclosure via Dashboard Feature
CVSS 7.5
CVE-2025-33004
MEDIUM
IBM Planning Analytics Local <2.1 - Privilege Escalation
CVSS 6.5
CVE-2025-5385
MEDIUM
JeeWMS < 2025-05-04 - Path Traversal via cgformTemplateController.do?doAdd
CVSS 6.3
CVE-2025-5381
LOW
Yifang CMS < 2.0.2 - Path Traversal via Admin Panel File Download
CVSS 2.7
CVE-2025-5380
MEDIUM
XueShengZhuSu <4d3f0ada - Path Traversal
CVSS 6.3
CVE-2025-4857
HIGH
Newsletters <= 4.9.9.9 - Authenticated Local File Inclusion via File Parameter
CVSS 7.2
CVE-2025-47952
CRITICAL
Traefik < 2.11.25 and < 3.4.1 - Path Traversal via URL-Encoded Path Bypass
CVSS 9.1
CVE-2025-5328
MEDIUM
chshcms mccms 2.7 - Path Traversal via Backups.php restore_del Function
CVSS 5.4
CVE-2025-48370
LOW
supabase/auth-js < 2.70.0 - Path Traversal via Invalid UUID Handling
CVE-2025-48744
MEDIUM
SIGB PMB < 8.0.1.2 - Local File Inclusion and Remote Code Execution
CVSS 6.4
CVE-2025-5161
MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via /safeEvent/download filename Parameter
CVSS 4.3
CVE-2025-5160
MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via Download Function Name Parameter
CVSS 4.3
CVE-2025-5159
MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via Download Name Parameter
CVSS 4.3
CVE-2025-5158
MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via downloadSoftware Filename Parameter
CVSS 4.3
CVE-2025-5157
MEDIUM
H3C SecCenter SMP-E1114P02 < 20250513 - Path Traversal via filePath Parameter in fileContent Function
CVSS 4.3
CVE-2025-48273
HIGH
WP Job Portal <2.3.2 - Path Traversal
CVSS 7.5
CVE-2025-47603
HIGH
Belingo belingoGeo <1.12.0 - Path Traversal
CVSS 7.5
CVE-2025-47535
HIGH
Opal Woo Custom Product Variation <1.2.0 - Path Traversal
CVSS 8.6
CVE-2025-47513
MEDIUM
James Laforge Infocob CRM Forms <2.4.0 - Path Traversal
CVSS 4.9
Details
Vulnerabilities
9,142
Exploit Likelihood
High