VulnSea

CWE-22

CVEs classified under CWE-22, newest first.

1061 CVEsRSS

CVE-2025-4517Critical· 9.4PoC
1y ago

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() o…

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() o…

▾ AbyssalEPSS 1.4%via NVD
CVE-2025-4330High· 7.5
1y ago

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

▾ TwilightEPSS 0.94%via NVD
CVE-2025-4138High· 7.5PoC
1y ago

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

▾ MidnightEPSS 1.4%via NVD
CVE-2024-12718Medium· 5.3
1y ago

Allows modifying some file metadata (e.g

Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extraction directory. You are affected by this vulnerability if using the tarfile module to ex…

▾ SunlitEPSS 0.77%via NVD
CVE-2024-7631Medium· 4.3
1y ago

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely…

▾ SunlitEPSS 0.50%via NVD
CVE-2024-48885Medium· 5.3
1y ago

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4…

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiRecorder 7.2.0 through 7.2.1, FortiRecorder 7.0.0 through 7.0.4, FortiVoice 7.0.0 through 7.0.4, FortiVoice 6.4.0 through 6.4…

▾ Sunlitfortinet · fortirecorderEPSS 0.79%via NVD
CVE-2024-57727High· 7.5CISA KEVPoC
1y ago

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests

SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. Th…

▾ Abyssalsimple-help · simplehelpEPSS 97%via NVD
CVE-2024-48884High· 7.5
1y ago

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS…

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiOS 7.6.0, FortiOS…

▾ Twilightfortinet · fortimanagerEPSS 15%via NVD
CVE-2024-12088Medium· 6.5
1y ago

A flaw was found in rsync

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vul…

▾ Sunlitsamba · rsyncEPSS 4.7%via NVD
CVE-2024-12087Medium· 6.5
1y ago

A path traversal vulnerability exists in rsync

A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the clien…

▾ Sunlitsamba · rsyncEPSS 2.3%via NVD
CVE-2024-55550Low· 2.7CISA KEVPoC
1y ago

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization

Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…

▾ Twilightmitel · micollabEPSS 38%via NVD
CVE-2024-11667High· 7.5CISA KEV
1y ago

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…

A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through V…

▾ Abyssalzyxel · zldEPSS 2.9%via NVD
CVE-2024-41713Critical· 9.1CISA KEVPoC
1y ago

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…

▾ Hadalmitel · micollabEPSS 98%via NVD
CVE-2024-9675High· 7.8⚖ disputed
1y ago

A vulnerability was found in Buildah

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the…

▾ Twilightbuildah_project · buildahEPSS 0.39%via NVD
CVE-2023-7260High· 7.5
2y ago

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4

Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4. The vulnerability could allow arbitrarily access files on the system.

▾ Twilightopentext · cx-e_voiceEPSS 0.52%via NVD
CVE-2023-7249Critical· 9.8
2y ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.

▾ Midnightopentext · directory_servicesEPSS 0.58%via NVD
CVE-2024-37129Medium· 6.7
2y ago

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability

Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.

▾ Sunlitdell · inventory_collectorEPSS 0.17%via NVD
CVE-2024-6127Critical· 9.8PoC
2y ago

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all crypt…

▾ AbyssalEPSS 10%via NVD
CVE-2024-1132High· 8.1
2y ago

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information withi…

▾ Twilightredhat · build_of_keycloakEPSS 1.6%via NVD
CVE-2024-27102Critical· 9.9PoC
2y ago

Wings is the server control plane for Pterodactyl Panel

Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions of Wings. The vulnerability can potentially be used to access files and directories on the host system. The full sco…

▾ Abyssalpterodactyl · wingsEPSS 0.55%via NVD
CVE-2024-21400Critical· 9.0
2y ago

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · confcomEPSS 2.2%via NVD
CVE-2024-22050High· 7.5
2y ago

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.

▾ Twilightboazsegev · iodineEPSS 0.91%via NVD
CVE-2023-34062High· 7.5
2y ago

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an applicati…

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack. Specifically, an applicati…

▾ Twilightbroadcom · reactor_nettyEPSS 1.1%via NVD
CVE-2023-47246Critical· 9.8CISA KEV0dayPoC
2y ago

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.

▾ Hadalsysaid · sysaidEPSS 99%via NVD
CVE-2023-27170High· 7.5PoC
2y ago

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

Xpand IT Write-back manager v2.3.1 allows attackers to perform a directory traversal via modification of the siteName parameter.

▾ Midnightxpand-it · write-back_managerEPSS 0.87%via NVD
CVE-2023-41266High· 8.2CISA KEVPoC
3y ago

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an un…

▾ Abyssalqlik · qlik_senseEPSS 85%via NVD
CVE-2023-38950High· 7.5CISA KEVPoC
3y ago

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload

A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.

▾ Abyssalzkteco · biotimeEPSS 92%via NVD
CVE-2023-27534Low· 3.7PoC⚖ disputed
3y ago

curl: SFTP path ~ resolving discrepancy (CVE-2023-27534)

A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicat…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 2.2%via CSAF
CVE-2022-2712Medium· 6.5
3y ago

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an remote unauthenticated attacker to acces…

▾ Sunliteclipse · glassfishEPSS 0.94%via NVD
CVE-2022-41352Critical· 9.8CISA KEVPoC
4y ago

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to …

▾ Hadalsynacor · zimbra_collaboration_suiteEPSS 95%via NVD
CWE-22 vulnerabilities (CVEs) — page 34 · VulnSea