CWE-22— Path Traversal
8,269 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 59 of 166
- CVE-2019-9610MEDIUMCVSS 4.3EG 4.32019-03-06
An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java.
- CVE-2019-9611MEDIUMCVSS 6.5EG 6.52019-03-06
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary fil…
- CVE-2019-9618CRITICALCVSS 9.8EG 9.82019-05-13
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
- CVE-2019-9622MEDIUMCVSS 4.3EG 4.32019-03-07
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as demonstrated by reading the user-data/save/backup.sql file.
- CVE-2019-9642CRITICALCVSS 9.8EG 9.82019-06-05
An issue was discovered in proxy.php in pydio-core in Pydio through 8.2.2. Through an unauthenticated request, it possible to evaluate malicious PHP code by placing it on the fourth line of a .php file, as demonstrated by a PoC.php created…
- CVE-2019-9648MEDIUMCVSS 5.3EG 5.32019-03-22
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exists using the SIZE command along with a \..\..\ substring, allowing an attacker to enumerate file existence based on the…
- CVE-2019-9649MEDIUMCVSS 5.3EG 5.32019-03-22
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence …
- CVE-2019-9662HIGHCVSS 7.5EG 7.52019-03-11
An issue was discovered in JTBC(PHP) 3.0.1.8. Its cache management module is flawed. An arbitrary file ending in "inc.php" can be deleted via a console/cache/manage.php?type=action&action=batch&batch=delete&ids=../ substring.
- CVE-2019-9686HIGHCVSS 8.8EG 8.82019-03-11
pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to…
- CVE-2019-9723HIGHCVSS 7.1EG 7.12019-05-30
LogicalDOC Community Edition 8.x before 8.2.1 has a path traversal vulnerability that allows reading arbitrary files and the creation of directories, in the class PluginRegistry.
- CVE-2019-9726HIGHCVSS 7.5EG 7.52019-05-13
Directory Traversal / Arbitrary File Read in eQ-3 AG Homematic CCU3 3.43.15 and earlier allows remote attackers to read arbitrary files of the device's filesystem. This vulnerability can be exploited by unauthenticated attackers with acces…
- CVE-2019-9852HIGHCVSS 7.8EG 7.82019-08-15
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, …
- CVE-2019-9854HIGHCVSS 7.8EG 7.82019-09-06
LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, …
- CVE-2019-9858HIGHCVSS 8.8EG 8.82019-05-29
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image upload in forms. When the Horde_Form_Type_image method onSubmit() is called on uploads, i…
- CVE-2019-9886HIGHCVSS 7.5EG 7.52019-07-11
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.
- CVE-2019-9889LOWCVSS 2.7EG 2.72019-03-21
In Vanilla before 2.6.4, a flaw exists within the getSingleIndex function of the AddonManager class. The issue results in a require call using a crafted type value, leading to Directory Traversal with File Inclusion. An attacker can levera…
- CVE-2019-9922HIGHCVSS 7.5EG 7.52019-03-29
An issue was discovered in the Harmis JE Messenger component 1.2.2 for Joomla!. Directory Traversal allows read access to arbitrary files.
- CVE-2019-9948CRITICALCVSS 9.1EG 9.12019-03-23
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/pa…
- CVE-2019-9960CRITICALCVSS 9.8EG 9.82019-03-24
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relative path.
- CVE-2020-0179HIGHCVSS 7.8EG 7.82020-06-11
In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is requ…
- CVE-2020-0520HIGHCVSS 7.8EG 7.82020-03-12
Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117 and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege or denial of service v…
- CVE-2020-0539MEDIUMCVSS 5.5EG 5.52020-06-15
Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially en…
- CVE-2020-10010HIGHCVSS 7.8EG 7.82020-12-08
A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A local attacker may be able to elevate their privileges.
- CVE-2020-10014MEDIUMCVSS 6.3EG 6.32020-12-08
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Big Sur 11.0.1. A malicious application may be able to break out of its sandbox.
- CVE-2020-10086MEDIUMCVSS 5.3EG 5.32020-03-13
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.
- CVE-2020-10366HIGHCVSS 7.5EG 7.52020-04-08
LogicalDoc before 8.3.3 allows /servlet.gupld Directory Traversal, a different vulnerability than CVE-2020-9423 and CVE-2020-10365.
- CVE-2020-10387MEDIUMCVSS 4.9EG 4.92020-03-12
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via the GET parameter file.
- CVE-2020-10457LOWCVSS 2.7EG 2.72020-03-12
Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) an…
- CVE-2020-10458MEDIUMCVSS 6.5EG 6.52020-03-12
Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (../) via the GET parameter crdir, when the GET parameter ac…
- CVE-2020-10459LOWCVSS 2.7EG 2.72020-03-12
Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot…
- CVE-2020-10506HIGHCVSS 7.5EG 7.52020-04-15
The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.
- CVE-2020-10564CRITICALCVSS 9.8EG 9.82020-03-13
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
- CVE-2020-10579HIGHCVSS 7.5EG 7.52021-03-25
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to list the content of arbitrary server directories accessible to the user running the application.
- CVE-2020-10584HIGHCVSS 7.5EG 7.52021-03-25
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote attackers to read arbitrary server files accessible to the user running the application.
- CVE-2020-10619CRITICALCVSS 9.1EG 9.12020-04-09
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
- CVE-2020-10631CRITICALCVSS 9.8EG 9.82020-04-09
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
- CVE-2020-10634CRITICALCVSS 9.1EG 9.12020-05-05
SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file structure of the affected device and access files that should be inaccessible.
- CVE-2020-10691MEDIUMCVSS 5.2EG 5.22020-04-30
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitizing the filename. A…
- CVE-2020-10696HIGHCVSS 8.8EG 8.82020-03-31
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere tha…
- CVE-2020-10794CRITICALCVSS 9.8EG 9.82020-05-07
Gira TKS-IP-Gateway 4.0.7.7 is vulnerable to unauthenticated path traversal that allows an attacker to download the application database. This can be combined with CVE-2020-10795 for remote root access.
- CVE-2020-1082HIGHCVSS 7.8EG 7.82020-05-21
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1021, CVE-2020-108…
- CVE-2020-10859MEDIUMCVSS 6.5EG 6.52020-05-05
Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request.
- CVE-2020-10875HIGHCVSS 7.5EG 7.52020-03-23
Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.
- CVE-2020-10953HIGHCVSS 7.5EG 7.52020-03-27
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
- CVE-2020-10977MEDIUMCVSS 5.5EG 5.52020-04-08
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
- CVE-2020-11073HIGHCVSS 7.9EG 7.92020-05-13
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0
- CVE-2020-11414HIGHCVSS 7.5EG 7.52020-03-31
An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other pa…
- CVE-2020-11420MEDIUMCVSS 6.5EG 6.52020-04-27
UPS Adapter CS141 before 1.90 allows Directory Traversal. An attacker with Admin or Engineer login credentials could exploit the vulnerability by manipulating variables that reference files and by doing this achieve access to files and dir…
- CVE-2020-11431CRITICALCVSS 9.1EG 9.12020-05-07
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
- CVE-2020-11439HIGHCVSS 8.8EG 8.82020-07-15
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →