Vulnerabilities (CVE)

Filtered by CWE-22
Total 10267 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46639 1 Correos 1 Correos 2026-06-17 N/A 7.5 HIGH
A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.
CVE-2022-46492 1 Nbnbk Project 1 Nbnbk 2026-06-17 N/A 6.5 MEDIUM
nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via the component /api/Index/getFileBinary.
CVE-2022-46309 1 Vitalsesp 1 Vitals Esp 2026-06-17 N/A 6.5 MEDIUM
Vitals ESP upload function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to access arbitrary system files.
CVE-2022-46306 1 Changingtec 1 Servisign 2026-06-17 N/A 8.8 HIGH
ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file path and allows the attacker to perform arbitrary system operation and disrupt of service.
CVE-2022-46305 1 Changingtec 1 Servisign 2026-06-17 N/A 6.5 MEDIUM
ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
CVE-2022-46256 1 Github 1 Enterprise Server 2026-06-17 N/A 8.8 HIGH
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the instance. This vulnerability was fixed in versions 3.3.17, 3.4.12, 3.5.9, 3.6.5 and 3.7.2. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2022-46255 1 Github 1 Enterprise Server 2026-06-17 N/A 9.8 CRITICAL
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpacking new content to prevent an arbitrary file overwrite bug. This vulnerability affected only version 3.7.0 of GitHub Enterprise Server and was fixed in version 3.7.1. This vulnerability was reported via the GitHub Bug Bounty program.
CVE-2022-46178 1 Metersphere 1 Metersphere 2026-06-17 N/A 7.4 HIGH
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testing and performance testing. Versions prior to 2.5.1 allow users to upload a file, but do not validate the file name, which may lead to upload file to any path. The vulnerability has been fixed in v2.5.1. There are no workarounds.
CVE-2022-46171 1 Tauri 1 Tauri 2026-06-17 N/A 6.8 MEDIUM
Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `?`, and `[...]` match file path literals and leading dots by default, which unintentionally exposes sub folder content of allowed paths. Scopes without the wildcards are not affected. As `**` allows for sub directories the behavior there is also as expected. The issue has been patched in the latest release and was backported into the currently supported 1.x branches. There are no known workarounds at the time of publication.
CVE-2022-46154 1 Kodcloud 1 Kodexplorer 2026-06-17 N/A 8.6 HIGH
Kodexplorer is a chinese language web based file manager and browser based code editor. Versions prior to 4.50 did not prevent unauthenticated users from requesting arbitrary files from the host OS file system. As a result any files available to the host process may be accessed by arbitrary users. This issue has been addressed in version 4.50. Users are advised to upgrade. There are no known workarounds for this issue.
CVE-2022-46137 1 Aerocms Project 1 Aerocms 2026-06-17 N/A 7.5 HIGH
AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.
CVE-2022-45969 1 Alistgo 1 Alist 2026-06-17 N/A 9.8 CRITICAL
Alist v3.4.0 is vulnerable to Directory Traversal,
CVE-2022-45921 1 Fusionauth 1 Fusionauth 2026-06-17 N/A 7.5 HIGH
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.
CVE-2022-45894 1 Planetestream 1 Planet Estream 2026-06-17 N/A 6.5 MEDIUM
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
CVE-2022-45867 1 Mybb 1 Mybb 2026-06-17 N/A 7.2 HIGH
MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achieve local file inclusion and execution.
CVE-2022-45866 2 Fedoraproject, Qpress Project 2 Fedora, Qpress 2026-06-17 N/A 5.3 MEDIUM
qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.
CVE-2022-45852 2026-06-17 N/A 6.5 MEDIUM
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FormAssembly / Drew Buschhorn WP-FormAssembly allows Path Traversal.This issue affects WP-FormAssembly: from n/a through 2.0.5.
CVE-2022-45833 1 Wp-ecommerce 1 Easy Wp Smtp 2026-06-17 N/A 6.8 MEDIUM
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
CVE-2022-45829 1 Wp-ecommerce 1 Easy Wp Smtp 2026-06-17 N/A 8.7 HIGH
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 at WordPress.
CVE-2022-45792 1 Omron 1 Sysmac Studio 2026-06-17 N/A 7.8 HIGH
Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overwriting files with the privileges of the logged-in user.