CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,142 vulnerabilities with CWE-22
CVE-2025-43566
MEDIUM
Adobe ColdFusion <= 2025.1, <= 2023.13, <= 2021.19 - Path Traversal and Arbitrary File Read
CVSS 6.8
CVE-2025-30387
CRITICAL
Azure AI Document Intelligence Studio - Path Traversal
CVSS 9.8
CVE-2025-31493
CRITICAL
Kirby < 3.9.8.3, 3.10.1.2, 4.7.1 - Path Traversal and Remote Code Execution via Dynamic Collection Name
CVSS 9.1
CVE-2025-30207
HIGH
Kirby <3.9.8.3, <3.10.1.2, <4.7.1 - Path Traversal
CVSS 7.5
CVE-2025-28055
HIGH
upset-gal-web 7.1.0 - Path Traversal and Arbitrary File Read via /api/music/v1/cover.ts
CVSS 7.5
CVE-2025-30159
CRITICAL
Kirby <3.9.8.3, 3.10.1.2, 4.7.1 - Path Traversal
CVSS 9.1
CVE-2025-40573
MEDIUM
SCALANCE LPE9403 < V4.0 HF0 - Path Traversal via Backup Restore
CVSS 4.4
CVE-2025-4632
CRITICAL
KEV
Samsung MagicINFO <21.1052 - Path Traversal
CVSS 9.8
CVE-2025-4545
MEDIUM
CTCMS 2.1.2 - Path Traversal via Tpl.php File Handler
CVSS 5.4
CVE-2025-4530
MEDIUM
feng_ha_ha/megagao ssm-erp & production_ssm 1.0 - Path Traversal
CVSS 4.3
CVE-2025-4529
MEDIUM
Seeyon Zhiyuan OA Web Application System 8.1 SP2 - Path Traversal via M3CoreController Download Function
CVSS 4.3
CVE-2025-4511
MEDIUM
vector4wang spring-boot-quick <20250422 - Path Traversal
CVSS 6.3
CVE-2025-2158
HIGH
WordPress Review Plugin <5.3.5 - Code Injection
CVSS 8.8
CVE-2025-4206
HIGH
Groundhogg <4.1.1.2 - Privilege Escalation
CVSS 7.2
CVE-2025-3897
MEDIUM
EUCookieLaw <2.7.2 - Info Disclosure
CVSS 5.9
CVE-2025-4377
HIGH
Sparx Systems Pro Cloud Server <6.0.165 - Path Traversal
CVE-2025-44021
LOW
OpenStack Ironic < 24.1.3, 24-24.1.3, 25-26.1.1, 27-29.0.1 - Arbitrary File Write via Image Handling
CVSS 2.8
CVE-2025-32820
HIGH
SonicWall SMA 100/200/210/400/410/500v Firmware < 10.2.1.15-81sv - Authenticated Path Traversal
CVSS 8.8
CVE-2025-20187
MEDIUM
Cisco Catalyst SD-WAN Manager - Path Traversal
CVSS 6.5
CVE-2025-20949
MEDIUM
Samsung Members < 5.0.00.11 - Path Traversal and Arbitrary File Write
CVSS 5.1
CVE-2025-22479
LOW
Dell Storage Manager 20.0.21 - Unauthenticated Path Traversal and Script Injection
CVSS 3.5
CVE-2025-4329
MEDIUM
74cms < 3.33.0 - Path Traversal via /index.php/index/download/index URL Parameter
CVSS 4.3
CVE-2025-46559
MEDIUM
Misskey <2025.4.1 - Info Disclosure
CVSS 5.4
CVE-2025-45239
MEDIUM
foxcms 2.0.6 - Path Traversal via DataBackup.php Restores Method
CVSS 5.3
CVE-2025-45238
CRITICAL
foxcms v1.2.5 - Arbitrary File Deletion via delRestoreSerie Method
CVSS 9.1
Details
Vulnerabilities
9,142
Exploit Likelihood
High