VYPR

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

BaseStableLikelihood: High

Description

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79

CVEs mapped to this weakness (10,395)

page 34 of 520
  • CVE-2025-9963CriSep 23, 2025
    risk 0.61cvss —epss 0.00

    A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with root permissions. This way the system can also be compromized.This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build …

  • CVE-2025-8426CriJul 31, 2025
    risk 0.61cvss 9.4epss 0.01

    Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of…

  • CVE-2025-49153CriJun 25, 2025
    risk 0.61cvss —epss 0.01

    The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.

  • CVE-2025-34022CriJun 20, 2025
    risk 0.61cvss —epss 0.01

    A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512, Targa 504, Targa Semplice, Targa 704 TKM, Targa 805, Targa 710 INOX, Targa 750, and Targa 704 ILB. The /common/get_file.php script in the “Download Archive…

  • CVE-2024-46986CriSep 18, 2024
    risk 0.61cvss 9.9epss 0.41

    Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon…

  • CVE-2024-36059CriJun 27, 2024
    risk 0.61cvss 9.4epss 0.01

    Directory Traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart upto and including version 2.3.5 allows attackers to read/write arbitrary files via the IEC61850 File Transfer protocol.

  • CVE-2024-6127CriJun 27, 2024
    risk 0.61cvss 9.8epss 0.10

    BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering…

  • CVE-2024-5505HigJun 6, 2024
    risk 0.61cvss 8.8epss 0.47

    NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR ProSAFE Network Management System. Authentication is…

  • CVE-2023-36534CriAug 8, 2023
    risk 0.61cvss 9.3epss 0.02

    Path traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via network access.

  • CVE-2023-34129HigJul 13, 2023
    risk 0.61cvss 8.8epss 0.41

    Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analytics allows an authenticated remote attacker to traverse the directory and extract arbitrary files using Zip Slip method to any location on the underlying…

  • CVE-2022-47875HigMay 2, 2023
    risk 0.61cvss 8.8epss 0.10

    A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

  • CVE-2023-22629HigFeb 14, 2023
    risk 0.61cvss 8.8epss 0.12

    An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any file and then move it anywhere on the server's filesystem.

  • CVE-2022-31588CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31587CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31586CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31585CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31584CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31583CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31582CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.01

    The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

  • CVE-2022-31581CriJul 11, 2022
    risk 0.61cvss 9.3epss 0.02

    The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.