CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,142 vulnerabilities with CWE-22
CVE-2024-6648
HIGH
AP Page Builder <4.0.0 - Path Traversal
CVSS 7.5
CVE-2024-11615
MEDIUM
Envolve Plugin <1.0 - Path Traversal
CVSS 5.3
CVE-2024-55913
MEDIUM
IBM Concert 1.0.0-1.0.5 - Path Traversal via URL Request
CVSS 5.3
CVE-2024-41792
HIGH
SENTRON 7KT PAC1260 Data Manager - Unauthenticated Path Traversal via Web Interface
CVSS 8.6
CVE-2024-54291
HIGH
PluginPass <0.9.10 - Path Traversal
CVSS 8.6
CVE-2024-12905
HIGH
tar-fs < 1.16.4, 2.0.0-2.1.2, 3.0.0-3.0.8 - Path Traversal and Arbitrary File Write via Malicious Tar Extraction
CVSS 7.5
CVE-2024-13920
MEDIUM
Order Export & Order Import for WooCommerce <= 2.6.0 - Authenticated Path Traversal via download_file() Function
CVSS 4.9
CVE-2024-9597
HIGH
parisneo/lollms < v12 - Path Traversal
CVSS 7.1
CVE-2024-9415
HIGH
superagi 0.0.14 - Path Traversal and Arbitrary File Write via File Upload
CVSS 8.8
CVE-2024-9362
HIGH
Polyaxon < latest - Unauthenticated Directory Traversal
CVSS 7.5
CVE-2024-8898
CRITICAL
lollms_web_ui V12 - Path Traversal and Arbitrary Directory Creation/Deletion via Install/Uninstall API Endpoints
CVSS 9.8
CVE-2024-8769
CRITICAL
aimhubio/aim <bb76afe - Path Traversal
CVSS 9.1
CVE-2024-8581
CRITICAL
parisneo/lollms-webui V12 - Path Traversal
CVSS 9.1
CVE-2024-8524
HIGH
modelscope/agentscope <0.0.4 - Path Traversal
CVSS 7.5
CVE-2024-8438
HIGH
modelscope/agentscope <0.0.4 - Path Traversal
CVSS 7.5
CVE-2024-8060
HIGH
OpenWebUI < 0.5.17 - Authenticated Path Traversal and Arbitrary File Write via Audio API Endpoint
CVSS 8.1
CVE-2024-7776
CRITICAL
onnx <= 1.16.1 - Path Traversal and Arbitrary File Overwrite via Malicious Tar File
CVSS 9.1
CVE-2024-7034
HIGH
open-webui 0.3.8 - Arbitrary File Write via Models Upload Endpoint
CVSS 7.2
CVE-2024-6851
HIGH
aimhubio/aim <3.22.0 - Path Traversal
CVSS 7.5
CVE-2024-5752
CRITICAL
Devika - Path Traversal via Crafted Project Name
CVSS 9.1
CVE-2024-12866
HIGH
qanything v2.0.0 - Path Traversal and Remote Code Execution
CVSS 7.5
CVE-2024-12217
MEDIUM
gradio - Path Traversal via NTFS Alternate Data Streams Bypass
CVSS 5.3
CVE-2024-12065
HIGH
haotian-liu/llava - Local File Inclusion via Gradio Web UI
CVSS 7.5
CVE-2024-11037
MEDIUM
binary-husky gpt_academic - Path Traversal via Absolute Path Bypass
CVSS 6.5
CVE-2024-10948
MEDIUM
binary-husky gpt_academic - Unauthenticated Arbitrary File Read via WebSocket Upload Path Manipulation
CVSS 6.5
Details
Vulnerabilities
9,142
Exploit Likelihood
High