Vulnerabilities (CVE)

Filtered by CWE-22
Total 8092 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-47512 2025-05-23 N/A 8.6 HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan allows Path Traversal. This issue affects Tainacan: from n/a through 0.21.14.
CVE-2025-47535 2025-05-23 N/A 8.6 HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation allows Path Traversal. This issue affects Opal Woo Custom Product Variation: from n/a through 1.2.0.
CVE-2024-55415 1 Thecontrolgroup 1 Voyager 2025-05-23 N/A 5.7 MEDIUM
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
CVE-2024-23721 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2025-05-23 N/A 7.5 HIGH
A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports information.
CVE-2018-5448 1 Medtronic 2 2090 Carelink Programmer, 2090 Carelink Programmer Firmware 2025-05-22 2.7 LOW 4.8 MEDIUM
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.
CVE-2025-41229 2025-05-21 N/A 8.2 HIGH
VMware Cloud Foundation contains a directory traversal vulnerability. A malicious actor with network access to port 443 on VMware Cloud Foundation may exploit this issue to access certain internal services.
CVE-2025-3223 2025-05-21 N/A 5.9 MEDIUM
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST on Windows (EGD Configuration Server modules) allows Path Traversal.This issue affects WorkstationST: WorkstationST V07.10.10C and earlier.
CVE-2025-4524 2025-05-21 N/A 9.8 CRITICAL
The Madara – Responsive and modern WordPress theme for manga sites theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.2 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
CVE-2025-5029 2025-05-21 5.5 MEDIUM 5.4 MEDIUM
A vulnerability has been found in Kingdee Cloud Galaxy Private Cloud BBC System up to 9.0 Patch April 2025 and classified as critical. Affected by this vulnerability is the function BaseServiceFactory.getFileUploadService.deleteFileAction of the file fileUpload/deleteFileAction.jhtml of the component File Handler. The manipulation of the argument filePath leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
CVE-2025-48017 2025-05-21 N/A 9.0 CRITICAL
Improper limitation of pathname in Circuit Provisioning and File Import applications allows modification and uploading of files
CVE-2025-4898 1 Munyweki 1 Student Result Management System 2025-05-21 5.5 MEDIUM 5.4 MEDIUM
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as critical. This vulnerability affects the function unlink of the file update_system.php of the component Logo File Handler. The manipulation of the argument old_logo leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-40199 1 Ec-cube 1 Ec-cube 2025-05-21 N/A 2.7 LOW
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0 to 4.1.2) allows a remote authenticated attacker with an administrative privilege to obtain the product's directory structure information.
CVE-2025-4912 1 Munyweki 1 Student Result Management System 2025-05-21 5.5 MEDIUM 5.4 MEDIUM
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/core/update_student.php of the component Image File Handler. The manipulation of the argument old_photo leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-2926 1 Adobe 1 Download Manager 2025-05-21 N/A 4.9 MEDIUM
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
CVE-2022-40082 2 Cloudwego, Microsoft 2 Hertz, Windows 2025-05-21 N/A 7.5 HIGH
Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function.
CVE-2021-33354 1 Htmly 1 Htmly 2025-05-20 N/A 8.1 HIGH
Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via modified file parameter.
CVE-2025-43566 1 Adobe 1 Coldfusion 2025-05-19 N/A 6.8 MEDIUM
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.
CVE-2025-30387 1 Microsoft 1 Azure Ai Document Intelligence Studio 2025-05-19 N/A 9.8 CRITICAL
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a network.
CVE-2024-2045 1 Opft 1 Session 2025-05-19 N/A 5.5 MEDIUM
Session version 1.17.5 allows obtaining internal application files and public files from the user's device without the user's consent. This is possible because the application is vulnerable to Local File Read via chat attachments.
CVE-2024-0849 1 Leanote 1 Desktop 2025-05-19 N/A 5.0 MEDIUM
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.