Vulnerabilities (CVE)

Filtered by CWE-22
Total 7187 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45894 1 Planetestream 1 Planet Estream 2025-04-14 N/A 6.5 MEDIUM
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
CVE-2023-0511 1 Forgerock 1 Java Policy Agents 2025-04-14 N/A 9.1 CRITICAL
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
CVE-2023-0339 1 Forgerock 1 Web Policy Agents 2025-04-14 N/A 9.1 CRITICAL
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
CVE-2021-39369 1 Philips 4 Myvue, Speech, Vue Motion and 1 more 2025-04-14 N/A 6.5 MEDIUM
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
CVE-2024-34315 1 Cmseasy 1 Cmseasy 2025-04-14 N/A 7.5 HIGH
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the fckedit_action method of /admin/template_admin.php. This vulnerability allows attackers to read arbitrary files.
CVE-2024-32163 1 Cmseasy 1 Cmseasy 2025-04-14 N/A 6.4 MEDIUM
CMSeasy 7.7.7.9 is vulnerable to code execution.
CVE-2023-40279 1 Openclinic Ga Project 1 Openclinic Ga 2025-04-14 N/A 7.5 HIGH
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to main.do.
CVE-2023-40280 1 Openclinic Ga Project 1 Openclinic Ga 2025-04-14 N/A 7.5 HIGH
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page parameter in a GET request to popup.jsp.
CVE-2016-5092 1 Fortinet 1 Fortiweb 2025-04-12 4.0 MEDIUM 4.9 MEDIUM
Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature.
CVE-2015-5638 1 Dena 1 H20 2025-04-12 4.3 MEDIUM N/A
Directory traversal vulnerability in H2O before 1.4.5 and 1.5.x before 1.5.0-beta2, when the file.dir directive is enabled, allows remote attackers to read arbitrary files via a crafted URL.
CVE-2015-7815 1 Matomo 1 Matomo 2025-04-12 7.5 HIGH N/A
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.
CVE-2014-2314 2 Atlassian, Microsoft 2 Jira, Windows 2025-04-12 4.3 MEDIUM N/A
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers to create arbitrary files via unspecified vectors.
CVE-2015-1365 1 Pixabay Images Project 1 Pixabay Images 2025-04-12 5.0 MEDIUM N/A
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows remote attackers to write to arbitrary files via a .. (dot dot) in the q parameter.
CVE-2014-5370 1 New Atlanta 1 Bluedragon 2025-04-12 7.5 HIGH N/A
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart.
CVE-2014-3865 1 Debian 1 Dpkg-dev 2025-04-12 6.4 MEDIUM N/A
Multiple directory traversal vulnerabilities in dpkg-source in dpkg-dev 1.3.0 allow remote attackers to modify files outside of the intended directories via a source package with a crafted Index: pseudo-header in conjunction with (1) missing --- and +++ header lines or (2) a +++ header line with a blank pathname.
CVE-2015-1192 1 Kgb Project 1 Kgb 2025-04-12 5.0 MEDIUM N/A
Absolute path traversal vulnerability in kgb 1.0b4 allows remote attackers to write to arbitrary files via a full pathname in a crafted archive.
CVE-2014-9372 1 Manageengine 1 Password Manager Pro 2025-04-12 6.4 MEDIUM N/A
Directory traversal vulnerability in the UploadAccountActivities servlet in ManageEngine Password Manager Pro (PMP) before 7103 allows remote attackers to delete arbitrary files via a .. (dot dot) in a filename.
CVE-2014-9767 2 Hiphop Virtual Machine For Php Project, Php 2 Hiphop Virtual Machine For Php, Php 2025-04-12 4.3 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty directories via a crafted ZIP archive.
CVE-2015-2067 1 Magmi Project 1 Magmi 2025-04-12 5.0 MEDIUM N/A
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
CVE-2016-0784 1 Apache 1 Openmeetings 2025-04-12 4.0 MEDIUM 6.5 MEDIUM
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.