Vulnerabilities (CVE)

Filtered by CWE-22
Total 10266 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-47942 1 Hacs 1 Home Assistant Community Store 2026-06-17 N/A 7.5 HIGH
Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive files by traversing directories via the /hacsfiles/ endpoint. Attackers can retrieve the .storage/auth file containing user credentials and refresh tokens, then craft valid JWT tokens to gain administrative access to Home Assistant instances.
CVE-2021-47921 2026-06-17 N/A 6.5 MEDIUM
Free Photo & Video Vault 0.0.2 contains a directory traversal web vulnerability that allows remote attackers to manipulate application path requests and access sensitive system files. Attackers can exploit the vulnerability without privileges to retrieve environment variables and access unauthorized system paths.
CVE-2021-47850 1 Yodinfo 1 Mini Mouse 2026-06-17 N/A 7.5 HIGH
Mini Mouse 9.2.0 contains a path traversal vulnerability that allows remote attackers to access arbitrary system files and directories through crafted HTTP requests. Attackers can retrieve sensitive files like win.ini and list contents of system directories such as C:\Users\Public by manipulating file and path parameters.
CVE-2021-47849 1 Yodinfo 1 Mini Mouse 2026-06-17 N/A 6.2 MEDIUM
Mini Mouse 9.3.0 contains a path traversal vulnerability that allows attackers to access sensitive system directories through the device information endpoint. Attackers can retrieve file lists from system directories like /usr, /etc, and /var by manipulating file path parameters in API requests.
CVE-2021-47795 2026-06-17 N/A 6.2 MEDIUM
GeoVision GeoWebServer 5.3.3 contains multiple vulnerabilities including local file inclusion, cross-site scripting, and remote code execution through improper input sanitization. Attackers can exploit the WebStrings.srf endpoint by manipulating path traversal and injection parameters to access system files and execute malicious scripts.
CVE-2021-47755 1 Softlinkint 1 Oliver V5 Library 2026-06-17 N/A 7.5 HIGH
Oliver Library Server v5 contains a file download vulnerability that allows unauthenticated attackers to access arbitrary system files through unsanitized input in the FileServlet endpoint. Attackers can exploit the vulnerability by manipulating the 'fileName' parameter to download sensitive files from the server's filesystem.
CVE-2021-47751 1 Phphtmledit 1 Rich Text Editor 2026-06-17 N/A 7.5 HIGH
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.
CVE-2021-47749 1 Youphptube 1 Youphptube 2026-06-17 N/A 5.5 MEDIUM
YouPHPTube <= 7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the 'lang' parameter in GET requests. Attackers can exploit the path traversal flaw in locale/function.php to include and view PHP files outside the intended directory by using directory traversal sequences.
CVE-2021-47724 1 Stvs 1 Provision 2026-06-17 N/A 6.5 MEDIUM
STVS ProVision 5.9.10 contains a path traversal vulnerability that allows authenticated attackers to access arbitrary files by manipulating the files parameter in the archive download functionality. Attackers can send GET requests to /archive/download with directory traversal sequences to read sensitive system files like /etc/passwd.
CVE-2021-46902 1 Meinbergglobal 1 Lantime Firmware 2026-06-17 N/A 7.2 HIGH
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
CVE-2021-46897 1 Wagtailcrx 1 Codered Extensions 2026-06-17 N/A 6.5 MEDIUM
views.py in Wagtail CRX CodeRed Extensions (formerly CodeRed CMS or coderedcms) before 0.22.3 allows upward protected/..%2f..%2f path traversal when serving protected media.
CVE-2021-46856 1 Huawei 2 Emui, Harmonyos 2026-06-17 N/A 7.5 HIGH
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2021-46830 1 Helpsystems 1 Goanywhere Managed File Transfer 2026-06-17 N/A 6.5 MEDIUM
A path traversal vulnerability exists within GoAnywhere MFT before 6.8.3 that utilize self-registration for the GoAnywhere Web Client. This vulnerability could potentially allow an external user who self-registers with a specific username and/or profile information to gain access to files at a higher directory level than intended.
CVE-2021-46421 1 Franklinfueling 2 Ts-550 Evo, Ts-550 Evo Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
Franklin Fueling Systems FFS T5 Series 1.8.7.7299 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
CVE-2021-46420 1 Franklinfueling 2 Ts-550 Evo, Ts-550 Evo Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
Franklin Fueling Systems FFS TS-550 evo 2.23.4.8936 is affected by an unauthenticated directory traversal vulnerability, which allows an attacker to obtain sensitive information.
CVE-2021-46417 1 Franklinfueling 2 Colibri, Colibri Firmware 2026-06-17 7.8 HIGH 7.5 HIGH
Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privileges in Franklin Fueling Systems Colibri Controller Module 1.8.19.8580.
CVE-2021-46381 1 Dlink 2 Dap-1620, Dap-1620 Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow].
CVE-2021-46203 1 Taogogo 1 Taocms 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
CVE-2021-46104 1 Webp 1 Webp Server Go 2026-06-17 5.0 MEDIUM 7.5 HIGH
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary file information on the server.
CVE-2021-45967 2 Igniterealtime, Pascom 2 Openfire, Cloud Phone System 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.