VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 2 of 520
  • CVE-2024-41713CriKEVOct 21, 2024
    risk 0.85cvss 9.1epss 0.98

    A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successful exploit could allow unauthorized…

  • CVE-2014-0780CriKEVApr 25, 2014
    risk 0.85cvss 9.8epss 0.74

    Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.

  • CVE-2024-4885CriKEVJun 25, 2024
    risk 0.84cvss 9.8epss 0.99

    In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\nmconsole privileges.

  • CVE-2021-20090CriKEVApr 29, 2021
    risk 0.84cvss 9.8epss 1.00

    A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

  • CVE-2024-1708HigKEVFeb 21, 2024
    risk 0.83cvss 8.4epss 0.95

    ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

  • CVE-2026-34909CriKEVMay 22, 2026
    risk 0.82cvss 10.0epss 0.65

    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.

  • CVE-2018-14847CriKEVAug 2, 2018
    risk 0.82cvss 9.1epss 0.96

    MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

  • CVE-2024-8963CriKEVSep 19, 2024
    risk 0.81cvss 9.4epss 0.99

    Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

  • CVE-2026-48282CriKEVJun 30, 2026
    risk 0.80cvss 10.0epss 0.42

    ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not…

  • CVE-2024-7399HigKEVAug 12, 2024
    risk 0.80cvss 8.8epss 0.92

    Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.

  • CVE-2024-32113CriKEVMay 8, 2024
    risk 0.80cvss 9.8epss 0.99

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.

  • CVE-2021-27065HigKEVMar 3, 2021
    risk 0.80cvss 7.8epss 1.00

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2019-3398HigKEVApr 18, 2019
    risk 0.80cvss 8.8epss 0.97

    Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or who has 'Admin' permissions for a space…

  • CVE-2024-28995HigKEVJun 6, 2024
    risk 0.79cvss 8.6epss 1.00

    SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

  • CVE-2021-38163CriKEVSep 14, 2021
    risk 0.79cvss 9.9epss 0.36

    SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable of running operating system commands with…

  • CVE-2018-20250HigKEVFeb 5, 2019
    risk 0.79cvss 7.8epss 0.96

    In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating…

  • CVE-2025-4632CriKEVMay 13, 2025
    risk 0.78cvss 9.8epss 0.24

    Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

  • CVE-2023-41266HigKEVAug 29, 2023
    risk 0.78cvss 8.2epss 0.85

    A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unauthenticated remote attacker to generate…

  • CVE-2022-30333HigKEVMay 9, 2022
    risk 0.78cvss 7.5epss 0.99

    RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

  • CVE-2026-85706CriKEVSep 12, 2026
    risk 0.77cvss 10.0epss 0.15

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path…