CWE-22

High likelihood

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Parent: CWE-706 - Use of Incorrectly-Resolved Name or Reference

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

9,143 vulnerabilities with CWE-22
CVE-2024-44255 HIGH
iPadOS < 18.1 - Path Traversal via Arbitrary Shortcuts Execution
CVSS 7.8
CVE-2024-50453 HIGH
The Pack Elementor addons <= 2.0.9 - PHP Local File Inclusion via Relative Path Traversal
CVSS 7.5
CVE-2024-49771 MEDIUM
MPXJ 8.3.5-13.5.0 - Path Traversal
CVSS 5.3
CVE-2024-48224 MEDIUM
funadmin 5.0.2 - Path Traversal and Arbitrary File Read via /curd/index/editfile
CVSS 4.9
CVE-2024-49766 MEDIUM
Werkzeug < 3.0.6 - Path Traversal on Windows via UNC Path Handling
CVSS 5.3
CVE-2024-37847 HIGH
MangoOS < 5.1.4 and Mango API < 4.5.5 - Arbitrary File Upload and Remote Code Execution
CVSS 8.8
CVE-2024-49381 HIGH
Plenti < 0.7.2 - Arbitrary File Deletion via /postLocal Endpoint
CVSS 7.5
CVE-2024-10379 MEDIUM
ESAFENET CDG 5 - Path Traversal via DecryptApplicationService decryptFileId Parameter
CVSS 4.3
CVE-2024-47027 HIGH
Lib/Sm < Shared Mem - Privilege Escalation
CVSS 7.8
CVE-2024-45842 MEDIUM
Toshibatec E-studio1058 Firmware < t1.01.h4.00 - Path Traversal
CVSS 5.3
CVE-2024-10011 HIGH
BuddyPress <14.1.0 - Path Traversal
CVSS 8.1
CVE-2024-49760 HIGH
OpenRefine <3.8.3 - Info Disclosure
CVSS 7.1
CVE-2024-49359 HIGH
ZimaOS < 1.2.5 - Authenticated Directory Traversal via File API Endpoint
CVSS 7.5
CVE-2024-48931 HIGH
ZimaOS < 1.2.5 - Authenticated Arbitrary File Read via File API Endpoint
CVSS 7.5
CVE-2024-47883 CRITICAL
OpenRefine Butterfly < 1.2.6 - Path Traversal and Server-Side Request Forgery via file:/ URL
CVSS 9.1
CVE-2024-45262 HIGH
GL-iNet Firmware - Path Traversal via /rpc Endpoint Params Parameter
CVSS 8.8
CVE-2024-10313 HIGH
iniNet Solutions SpiderControl SCADA PC HMI Editor - Path Traversal
CVSS 8.0
CVE-2024-48213 MEDIUM
RockOA 2.6.5 - Path Traversal in beifenAction.php
CVSS 4.3
CVE-2024-20379 MEDIUM
Cisco Secure Firewall Management Center - Info Disclosure
CVSS 6.5
CVE-2024-41717 CRITICAL
Kieback & Peter's DDC4000 - Path Traversal
CVSS 9.8
CVE-2024-35308 HIGH
Pandora FMS 700-777.3 - Authenticated Arbitrary File Read via Server Plugins Section
CVSS 8.8
CVE-2024-41713 CRITICAL KEV
Mitel MiCollab < 9.8.1.201 - Unauthenticated Path Traversal in NuPoint Unified Messaging
CVSS 9.1
CVE-2024-49366 HIGH
nginxui/nginx_ui < 2.0.0-beta.35 - Path Traversal and Arbitrary File Write
CVSS 7.5
CVE-2024-45309 HIGH
OneDev Unauthenticated Arbitrary File Read
CVSS 7.5
CVE-2024-47742 HIGH
Linux Kernel - Path Traversal via Firmware Loader
CVSS 7.8
Details
Vulnerabilities 9,143
Exploit Likelihood High