Vulnerabilities (CVE)

Filtered by CWE-22
Total 8484 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-24934 1 Elementor 1 Website Builder 2025-01-29 N/A 8.5 HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Elementor Elementor Website Builder allows Manipulating Web Input to File System Calls.This issue affects Elementor Website Builder: from n/a through 3.19.0.
CVE-2023-25289 1 Virtualreception 1 Digital Reciptie 2025-01-29 N/A 7.5 HIGH
Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.
CVE-2023-30268 2 Cltphp, Microsoft 2 Cltphp, Windows 2025-01-29 N/A 9.8 CRITICAL
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
CVE-2023-32235 1 Ghost 1 Ghost 2025-01-29 N/A 7.5 HIGH
Ghost before 5.42.1 allows remote attackers to read arbitrary files within the active theme's folder via /assets/built%2F..%2F..%2F/ directory traversal. This occurs in frontend/web/middleware/static-theme.js.
CVE-2023-47178 1 Posimyth 1 The Plus Addons For Elementor 2025-01-29 N/A 8.6 HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro allows PHP Local File Inclusion.This issue affects The Plus Addons for Elementor Pro: from n/a through 5.2.8.
CVE-2023-28127 1 Ivanti 1 Avalanche 2025-01-28 N/A 7.5 HIGH
A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.
CVE-2023-27562 1 N8n 1 N8n 2025-01-27 N/A 6.5 MEDIUM
The n8n package 0.218.0 for Node.js allows Directory Traversal.
CVE-2023-26126 1 M.static Project 1 M.static 2025-01-27 N/A 7.5 HIGH
All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
CVE-2023-31477 1 Gl-inet 64 Gl-a1300, Gl-a1300 Firmware, Gl-ap1300 and 61 more 2025-01-27 N/A 7.5 HIGH
A path traversal issue was discovered on GL.iNet devices before 3.216. Through the file sharing feature, it is possible to share an arbitrary directory, such as /tmp or /etc, because there is no server-side restriction to limit sharing to the USB path.
CVE-2023-30172 1 Lfprojects 1 Mlflow 2025-01-27 N/A 7.5 HIGH
A directory traversal vulnerability in the /get-artifact API method of the mlflow platform up to v2.0.1 allows attackers to read arbitrary files on the server via the path parameter.
CVE-2023-29986 1 Spring-boot-actuator-logview Project 1 Spring-boot-actuator-logview 2025-01-27 N/A 5.3 MEDIUM
spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.
CVE-2023-23169 1 Synapsoft 1 Pdfocus 2025-01-27 N/A 6.5 MEDIUM
Synapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.
CVE-2024-3848 1 Lfprojects 1 Mlflow 2025-01-24 N/A 7.5 HIGH
A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously addressed CVE-2023-6909. The vulnerability arises from the application's handling of artifact URLs, where a '#' character can be used to insert a path into the fragment, effectively skipping validation. This allows an attacker to construct a URL that, when processed, ignores the protocol scheme and uses the provided path for filesystem access. As a result, an attacker can read arbitrary files, including sensitive information such as SSH and cloud keys, by exploiting the way the application converts the URL into a filesystem path. The issue stems from insufficient validation of the fragment portion of the URL, leading to arbitrary file read through path traversal.
CVE-2020-13377 1 Loadbalancer 1 Enterprise Va Max 2025-01-24 N/A 8.1 HIGH
The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and write access to sensitive files.
CVE-2024-7634 1 F5 2 Nginx Agent, Nginx Instance Manager 2025-01-24 N/A 4.9 MEDIUM
NGINX Agent's "config_dirs" restriction feature allows a highly privileged attacker to gain the ability to write/overwrite files outside of the designated secure directory.
CVE-2024-2552 1 Paloaltonetworks 1 Pan-os 2025-01-24 N/A 6.0 MEDIUM
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall.
CVE-2023-32985 1 Jenkins 1 Sidebar Link 2025-01-23 N/A 4.3 MEDIUM
Jenkins Sidebar Link Plugin 2.2.1 and earlier does not restrict the path of files in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
CVE-2024-26261 1 Hgiga 4 Oaklouds-organization-2.0, Oaklouds-organization-3.0, Oaklouds-webbase-2.0 and 1 more 2025-01-23 N/A 9.8 CRITICAL
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulnerability. Attackers can put file path in specific request parameters, allowing them to download the file without login. Furthermore, the file will be deleted after being downloaded.
CVE-2024-0818 1 Paddlepaddle 1 Paddlepaddle 2025-01-23 N/A 9.1 CRITICAL
Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6
CVE-2024-38768 1 Webangon 1 The Pack Elementor Addons 2025-01-22 N/A 4.3 MEDIUM
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Webangon The Pack Elementor addons allows PHP Local File Inclusion, Path Traversal.This issue affects The Pack Elementor addons: from n/a through 2.0.8.6.