CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,143 vulnerabilities with CWE-22
CVE-2024-11313
CRITICAL
DVC 6.0-6.3 - Unauthenticated Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2024-11312
CRITICAL
DVC 6.0-<6.4 - Unauthenticated Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2024-11311
CRITICAL
DVC 6.0-6.3 - Unauthenticated Path Traversal and Arbitrary File Write
CVSS 9.8
CVE-2024-11310
HIGH
DVC 6.0-6.3 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2024-11309
HIGH
DVC 6.0-6.3 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2024-9935
HIGH
PDF Generator Addon - Path Traversal
CVSS 7.5
CVE-2024-44625
HIGH
Gogs <= 0.13.0 - Path Traversal via editFilePost Function
CVSS 8.8
CVE-2024-50649
CRITICAL
python_book V1.0 - Arbitrary File Upload via User Avatar Upload Function
CVSS 9.8
CVE-2024-50648
CRITICAL
yshopmall V1.0 - Arbitrary File Upload and Remote Code Execution via JSP File Parsing
CVSS 9.8
CVE-2024-41784
HIGH
IBM Sterling Secure Proxy <6.1.0.0 - Path Traversal
CVSS 7.5
CVE-2024-11239
MEDIUM
Landray EKP < 16.0 - Path Traversal via Import API DeleteFile Function
CVSS 5.4
CVE-2024-11238
MEDIUM
Landray EKP < 16.0 - Path Traversal via delPreviewFile directoryPath Parameter
CVSS 6.5
CVE-2024-42499
MEDIUM
FitNesse <20241026 - Path Traversal
CVSS 5.3
CVE-2024-52396
MEDIUM
WOLF - WordPress Posts Bulk Editor and Products Manager Professional < 1.0.8.4 - Path Traversal via CSV Import
CVSS 4.9
CVE-2024-52378
HIGH
Labs64 DigiPass <0.3.0 - Path Traversal
CVSS 7.5
CVE-2024-52371
HIGH
DonnellC Global Gateway e4-2.0 - Path Traversal
CVSS 8.6
CVE-2024-11210
MEDIUM
EyouCMS 1.51 - Path Traversal via FilemanagerLogic.php editFile Function
CVSS 5.4
CVE-2024-50843
MEDIUM
PHPGurukul User Registration & Login and User Management System 3.2 - Directory Listing via /loginsystem/assets
CVSS 5.3
CVE-2024-11215
MEDIUM
EasyPHP Webserver 14.1 - Path Traversal via Consecutive '/...%5c' Strings
CVSS 6.5
CVE-2024-47916
HIGH
Boa web server 0.94.14rc21 - Path Traversal
CVSS 7.5
CVE-2024-45253
HIGH
Avigilon VideoIQ iCVR HD camera - Path Traversal
CVSS 7.5
CVE-2024-2552
MEDIUM
PAN-OS >=10.2.0 <10.2.7 - Authenticated Command Injection via Management Plane
CVSS 6.0
CVE-2024-21799
HIGH
Intel(R) Extension for Transformers <1.5 - Privilege Escalation
CVSS 7.1
CVE-2024-52292
HIGH
Craft CMS 3.5.13-4.12.7 and 5.0.0-alpha.1-5.4.8 - Authenticated Path Traversal via dataUrl Function
CVSS 7.7
CVE-2024-52291
HIGH
Craft CMS 4.0.0-4.12.4 and 5.0.0-RC1-5.4.5 - Authenticated Path Traversal via Double file:// Scheme
CVSS 8.4
Details
Vulnerabilities
9,143
Exploit Likelihood
High