CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,495 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 11 of 210
- CVE-2024-5980CRITICALCVSS 9.8EG 9.82024-06-27
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp is running with the plugin_server, attackers can deploy ma…
- CVE-2024-34313CRITICALCVSS 9.8EG 9.82024-06-24
An issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.
- CVE-2024-33879CRITICALCVSS 9.8EG 9.82024-06-24
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal …
- CVE-2023-45197CRITICALCVSS 9.8EG 9.82024-06-21
The file upload plugin in Adminer and AdminerEvo allows an attacker to upload a file with a table name of “..” to the root of the Adminer directory. The attacker can effectively guess the name of the uploaded file and execute it. Admin…
- CVE-2024-4098CRITICALCVSS 9.8EG 9.82024-06-20
The Shariff Wrapper plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 4.6.13 via the shariff3uu_fetch_sharecounts function. This allows unauthenticated attackers to include and execute arbitrary f…
- CVE-2024-27174CRITICALCVSS 9.8EG 9.82024-06-14
Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower …
- CVE-2024-27173CRITICALCVSS 9.8EG 9.82024-06-14
Remote Command program allows an attacker to get Remote Code Execution by overwriting existing Python files containing executable code. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute…
- CVE-2024-27145CRITICALCVSS 9.8EG 9.82024-06-14
The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An attacker can overwrite any insecure files. This vulnerability can be executed in combinat…
- CVE-2024-27144CRITICALCVSS 9.8EG 9.82024-06-14
The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure files. And the Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. …
- CVE-2024-4320CRITICALCVSS 9.8EG 9.82024-06-06
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to i…
- CVE-2024-3429CRITICALCVSS 9.8EG 9.82024-06-06
A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability allows for arbitrary file…
- CVE-2024-3322CRITICALCVSS 9.8EG 9.82024-06-06
A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation of a pathname to a restricted dire…
- CVE-2024-3234CRITICALCVSS 9.8EG 9.82024-06-06
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, t…
- CVE-2024-2624CRITICALCVSS 9.8EG 9.82024-06-06
A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in `./lollms-webui/lollms_core/lollms/server/endpoints/lollms…
- CVE-2024-2360CRITICALCVSS 9.8EG 9.82024-06-06
parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' and 'PDF LaTeX path' settings. An attacker can exploit this…
- CVE-2024-34832CRITICALCVSS 9.8EG 9.82024-06-06
Directory Traversal vulnerability in CubeCart v.6.5.5 and before allows an attacker to execute arbitrary code via a crafted file uploaded to the _g and node parameters.
- CVE-2024-37273CRITICALCVSS 9.8EG 9.82024-06-04
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2024-27776CRITICALCVSS 9.8EG 9.82024-06-02
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
- CVE-2024-34854CRITICALCVSS 9.8EG 9.82024-05-28
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`
- CVE-2024-35324CRITICALCVSS 9.8EG 9.82024-05-28
Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php.
- CVE-2024-5147CRITICALCVSS 9.8EG 9.82024-05-22
The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attacke…
- CVE-2023-40498CRITICALCVSS 9.8EG 9.82024-05-03
LG Simple Editor cp Command Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to expl…
- CVE-2023-40497CRITICALCVSS 9.8EG 9.82024-05-03
LG Simple Editor saveXml Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required to exploit…
- CVE-2023-40493CRITICALCVSS 9.8EG 9.82024-05-03
LG Simple Editor copySessionFolder Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG Simple Editor. Authentication is not required …
- CVE-2023-32165CRITICALCVSS 9.8EG 9.82024-05-03
D-Link D-View TftpReceiveFileHandler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of D-Link D-View. Authentication is not required t…
- CVE-2024-33350CRITICALCVSS 9.8EG 9.82024-04-29
Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensitive information via the include/model/file.php component.
- CVE-2024-31818CRITICALCVSS 9.8EG 9.82024-04-12
Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.
- CVE-2024-2221CRITICALCVSS 9.8EG 9.82024-04-10
qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to up…
- CVE-2024-1511CRITICALCVSS 9.8EG 9.82024-04-10
The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This flaw allows an unauthenticated attacker to read, write, and in certain configurations exec…
- CVE-2024-31849CRITICALCVSS 9.8EG 9.82024-04-05
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the applica…
- CVE-2024-31848CRITICALCVSS 9.8EG 9.82024-04-05
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedded Jetty server, which could allow an unauthenticated remote attacker to gain complete administrative access to the appl…
- CVE-2024-27768CRITICALCVSS 9.8EG 9.82024-03-18
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
- CVE-2024-28222CRITICALCVSS 9.8EG 9.82024-03-07
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenticated attacker to upload and execute a custom file.
- CVE-2024-27764CRITICALCVSS 9.8EG 9.82024-03-05
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
- CVE-2024-25830CRITICALCVSS 9.8EG 9.82024-02-29
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A su…
- CVE-2024-26261CRITICALCVSS 9.8EG 9.82024-02-15
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. …
- CVE-2023-40266CRITICALCVSS 9.8EG 9.82024-02-08
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
- CVE-2024-24398CRITICALCVSS 9.8EG 9.82024-02-06
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the fileName parameter of the Save function.
- CVE-2023-6989CRITICALCVSS 9.8EG 9.82024-02-05
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it poss…
- CVE-2023-7077CRITICALCVSS 9.8EG 9.82024-02-05
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8) allows an attac…
- CVE-2024-24482CRITICALCVSS 9.8EG 9.82024-02-02
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
- CVE-2024-23827CRITICALCVSS 9.8EG 9.82024-01-29
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does not check if the provided user input is a certification/key and allows to write into arbitr…
- CVE-2023-6623CRITICALCVSS 9.8EG 9.82024-01-15
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to Local File Inclusion attacks.
- CVE-2023-49569CRITICALCVSS 9.8EG 9.82024-01-12
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker to create and amend files across the filesystem. In the worse case scenario, remote code execution could be achieved. A…
- CVE-2023-45723CRITICALCVSS 9.8EG 9.82024-01-03
HCL DRYiCE MyXalytics is impacted by path traversal vulnerability which allows file upload capability. Certain endpoints permit users to manipulate the path (including the file name) where these files are stored on the server.
- CVE-2023-45722CRITICALCVSS 9.8EG 9.82024-01-03
HCL DRYiCE MyXalytics is impacted by path traversal arbitrary file read vulnerability because it uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent di…
- CVE-2023-7134CRITICALCVSS 9.8EG 9.82023-12-28
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../filedir'. The attack ma…
- CVE-2023-6190CRITICALCVSS 9.8EG 9.82023-12-27
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in İzmir Katip Çelebi University University Information Management System allows Absolute Path Traversal. This issue affects University Informa…
- CVE-2023-5991CRITICALCVSS 9.8EG 9.82023-12-26
The Hotel Booking Lite WordPress plugin before 4.8.5 does not validate file paths provided via user input, as well as does not have proper CSRF and authorisation checks, allowing unauthenticated users to download and delete arbitrary files…
- CVE-2023-6972CRITICALCVSS 9.8EG 9.82023-12-23
The Backup Migration plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.9 via the 'content-backups' and 'content-name', 'content-manifest', or 'content-bmitmp' and 'content-identy' HTTP headers. …
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →