CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,142 vulnerabilities with CWE-22
CVE-2024-54382
MEDIUM
BoldThemes Bold Page Builder <5.1.5 - Path Traversal
CVSS 4.9
CVE-2024-54380
HIGH
Filippo Bodei WP Cookies Enabler <1.0.1 - Path Traversal
CVSS 7.5
CVE-2024-54375
HIGH
Woolook <= 1.7.0 - PHP Local File Inclusion via Path Traversal
CVSS 7.5
CVE-2024-54374
HIGH
Sogrid <= 1.5.6 - PHP Local File Inclusion via Path Traversal
CVSS 7.5
CVE-2024-54373
HIGH
EduAdmin Booking <5.2.0 - Path Traversal
CVSS 7.5
CVE-2024-12362
MEDIUM
InvoicePlane <= 1.6.1 - Path Traversal via Invoice Download Argument
CVSS 4.3
CVE-2024-55970
HIGH
Syncfusion Essential Studio for ASP.NET MVC <27.1.55 - Path Traversal
CVSS 7.5
CVE-2024-54259
MEDIUM
DELUCKS SEO <2.5.5 - Path Traversal
CVSS 6.5
CVE-2024-11834
CRITICAL
PlexTrac 1.61.3-2.8.1 - Path Traversal and Arbitrary File Write
CVSS 9.1
CVE-2024-11833
CRITICAL
PlexTrac 1.61.3-2.8.1 - Path Traversal and Arbitrary File Write
CVSS 9.1
CVE-2024-8647
MEDIUM
GitLab 15.2-17.4.6, 17.5 < 17.5.4, 17.6 < 17.6.2 - Anti-CSRF Token Leak via Harbor Integration
CVSS 5.4
CVE-2024-55659
MEDIUM
SiYuan < 3.1.16 - Unauthenticated Arbitrary File Write and Stored Cross-Site Scripting via Asset Upload Endpoint
CVSS 5.4
CVE-2024-55658
HIGH
SiYuan < 3.1.16 - Unauthenticated Arbitrary File Read via Path Traversal
CVSS 7.5
CVE-2024-55657
HIGH
SiYuan < 3.1.16 - Path Traversal via Template Render Endpoint
CVSS 7.5
CVE-2024-54489
HIGH
macOS < 13.7.2, < 14.7.2, < 15.2 - Unauthenticated Arbitrary Code Execution via Mount Command
CVSS 7.8
CVE-2024-55587
HIGH
python-libarchive through 4.2.1 - Path Traversal via ZipFile.extract and ZipFile.extractall
CVSS 8.8
CVE-2024-49082
MEDIUM
Windows 10/11, Server 2008-2012 - Information Disclosure via File Explorer Path Traversal
CVSS 6.8
CVE-2024-12482
MEDIUM
cjbi wetech-cms 1.0/1.1/1.2 - Path Traversal via Database Backup Handler
CVSS 4.3
CVE-2024-55550
LOW
KEV
MiCollab < 9.8.1.201 - Authenticated Path Traversal
CVSS 2.7
CVE-2024-55602
HIGH
pwndoc < 1.2.1 - Authenticated Path Traversal via Template File Extension
CVSS 7.6
CVE-2024-45709
MEDIUM
SolarWinds Web Help Desk < 12.8.4 - Local File Read via Path Traversal
CVSS 5.3
CVE-2024-10708
MEDIUM
System Dashboard WordPress Plugin < 2.8.15 - Authenticated Path Traversal
CVSS 4.9
CVE-2024-21542
HIGH
luigi < 3.6.0 - Arbitrary File Write via Archive Extraction
CVSS 8.6
CVE-2024-50626
HIGH
Digi ConnectPort LTS Firmware < 1.4.12 - Path Traversal in WebFS
CVSS 8.8
CVE-2024-53790
HIGH
Ogun Labs Lenxel Core - Path Traversal
CVSS 7.5
Details
Vulnerabilities
9,142
Exploit Likelihood
High