CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,142 vulnerabilities with CWE-22
CVE-2024-6648 HIGH
AP Page Builder <4.0.0 - Path Traversal
CVSS 7.5
CVE-2024-11615 MEDIUM
Envolve Plugin <1.0 - Path Traversal
CVSS 5.3
CVE-2024-55913 MEDIUM
IBM Concert 1.0.0-1.0.5 - Path Traversal via URL Request
CVSS 5.3
CVE-2024-41792 HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated Path Traversal via Web Interface
CVSS 8.6
CVE-2024-54291 HIGH
PluginPass <0.9.10 - Path Traversal
CVSS 8.6
CVE-2024-12905 HIGH
tar-fs < 1.16.4, 2.0.0-2.1.2, 3.0.0-3.0.8 - Path Traversal and Arbitrary File Write via Malicious Tar Extraction
CVSS 7.5
CVE-2024-13920 MEDIUM
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated Path Traversal via download_file() Function
CVSS 4.9
CVE-2024-9597 HIGH
parisneo/lollms < v12 - Path Traversal
CVSS 7.1
CVE-2024-9415 HIGH
superagi 0.0.14 - Path Traversal and Arbitrary File Write via File Upload
CVSS 8.8
CVE-2024-9362 HIGH
Polyaxon < latest - Unauthenticated Directory Traversal
CVSS 7.5
CVE-2024-8898 CRITICAL
lollms_web_ui V12 - Path Traversal and Arbitrary Directory Creation/Deletion via Install/Uninstall API Endpoints
CVSS 9.8
CVE-2024-8769 CRITICAL
aimhubio/aim <bb76afe - Path Traversal
CVSS 9.1
CVE-2024-8581 CRITICAL
parisneo/lollms-webui V12 - Path Traversal
CVSS 9.1
CVE-2024-8524 HIGH
modelscope/agentscope <0.0.4 - Path Traversal
CVSS 7.5
CVE-2024-8438 HIGH
modelscope/agentscope <0.0.4 - Path Traversal
CVSS 7.5
CVE-2024-8060 HIGH
OpenWebUI < 0.5.17 - Authenticated Path Traversal and Arbitrary File Write via Audio API Endpoint
CVSS 8.1
CVE-2024-7776 CRITICAL
onnx <= 1.16.1 - Path Traversal and Arbitrary File Overwrite via Malicious Tar File
CVSS 9.1
CVE-2024-7034 HIGH
open-webui 0.3.8 - Arbitrary File Write via Models Upload Endpoint
CVSS 7.2
CVE-2024-6851 HIGH
aimhubio/aim <3.22.0 - Path Traversal
CVSS 7.5
CVE-2024-5752 CRITICAL
Devika - Path Traversal via Crafted Project Name
CVSS 9.1
CVE-2024-12866 HIGH
qanything v2.0.0 - Path Traversal and Remote Code Execution
CVSS 7.5
CVE-2024-12217 MEDIUM
gradio - Path Traversal via NTFS Alternate Data Streams Bypass
CVSS 5.3
CVE-2024-12065 HIGH
haotian-liu/llava - Local File Inclusion via Gradio Web UI
CVSS 7.5
CVE-2024-11037 MEDIUM
binary-husky gpt_academic - Path Traversal via Absolute Path Bypass
CVSS 6.5
CVE-2024-10948 MEDIUM
binary-husky gpt_academic - Unauthenticated Arbitrary File Read via WebSocket Upload Path Manipulation
CVSS 6.5
Details
Vulnerabilities 9,142
Exploit Likelihood High