Vulnerabilities (CVE)

Filtered by CWE-22
Total 10246 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-42125 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-07-09 N/A 7.5 HIGH
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.
CVE-2022-42123 1 Liferay 2 Digital Experience Platform, Liferay Portal 2026-07-09 N/A 7.5 HIGH
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7.4 before update 19 allows attackers to create or overwrite existing files on the filesystem via the installation of a malicious Elasticsearch Sidecar plugin.
CVE-2022-40123 1 Mojoportal 1 Mojoportal 2026-07-09 N/A 6.5 MEDIUM
mojoPortal v2.7 was discovered to contain a path traversal vulnerability via the "f" parameter at /DesignTools/CssEditor.aspx. This vulnerability allows authenticated attackers to read arbitrary files in the system.
CVE-2022-38614 1 Bpcbt 1 Smartvista Cardgen 2026-07-09 N/A 7.5 HIGH
An issue in the IGB Files and OutfileService features of SmartVista Cardgen v3.28.0 allows attackers to list and download arbitrary files via modifying the PATH parameter.
CVE-2022-38613 1 Bpcbt 1 Smartvista Cardgen 2026-07-09 N/A 6.5 MEDIUM
A Path Traversal vulnerability in SmartVista Cardgen v3.28.0 allows authenticated attackers to read arbitrary files in the system.
CVE-2022-37700 1 Easycorp 1 Zentao 2026-07-09 N/A 7.5 HIGH
Zentao Demo15 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: URL : view-source:https://demo15.zentao.pm/user-login.html/zentao/index.php?mode=getconfig.
CVE-2022-34026 1 Icecoder 1 Icecoder 2026-07-09 N/A 7.5 HIGH
ICEcoder v8.1 allows attackers to execute a directory traversal.
CVE-2022-28981 1 Liferay 1 Liferay Portal 2026-07-09 N/A 7.5 HIGH
Path traversal vulnerability in the Hypermedia REST APIs module in Liferay Portal 7.4.0 through 7.4.2 allows remote attackers to access files outside of com.liferay.headless.discovery.web/META-INF/resources via the `parameter` parameter.
CVE-2022-28945 1 Webbank 1 Webcube 2026-07-09 7.5 HIGH 9.8 CRITICAL
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
CVE-2022-24992 1 Qr Code Generator Project 1 Qr Code Generator 2026-07-09 N/A 7.5 HIGH
A vulnerability in the component process.php of QR Code Generator v5.2.7 allows attackers to perform directory traversal.
CVE-2022-23347 1 Bigantsoft 1 Bigant Server 2026-07-09 5.0 MEDIUM 7.5 HIGH
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
CVE-2022-22914 1 Ovidentia 1 Ovidentia 2026-07-09 5.0 MEDIUM 7.5 HIGH
An incorrect access control issue in the component FileManager of Ovidentia CMS 6.0 allows authenticated attackers to to view and download content in the upload directory via path traversal.
CVE-2021-45783 1 Bookeen 2 Notea, Notea Firmware 2026-07-09 2.1 LOW 4.6 MEDIUM
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to obtain sensitive information.
CVE-2021-45418 1 Starcharge 4 Nova 360 Cabinet, Nova 360 Cabinet Firmware, Titan 180 Premium and 1 more 2026-07-09 6.5 MEDIUM 8.8 HIGH
Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0.
CVE-2021-44674 1 Opmantek 1 Open-audit 2026-07-09 4.0 MEDIUM 6.5 MEDIUM
An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticated attacker to read file outside of the restricted directory.
CVE-2021-41449 1 Netgear 6 Rax35, Rax35 Firmware, Rax38 and 3 more 2026-07-09 3.6 LOW 7.1 HIGH
A path traversal attack in web interfaces of Netgear RAX35, RAX38, and RAX40 routers before v1.0.4.102, allows a remote unauthenticated attacker to gain access to sensitive restricted information, such as forbidden files of the web application, via sending a specially crafted HTTP packet.
CVE-2021-37500 1 Reprisesoftware 1 Reprise License Manager 2026-07-09 N/A 8.1 HIGH
Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics function that allows RLM users with sufficient privileges to overwrite any file the on the server.
CVE-2021-29006 1 Rconfig 1 Rconfig 2026-07-09 4.0 MEDIUM 6.5 MEDIUM
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any file on the server.
CVE-2021-27328 1 Yeastar 2 Neogate Tg400, Neogate Tg400 Firmware 2026-07-09 4.0 MEDIUM 6.5 MEDIUM
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware and can read sensitive information, such as a password or decryption key.
CVE-2024-41628 2026-07-09 N/A 7.5 HIGH
Directory Traversal vulnerability in Severalnines Cluster Control 1.9.8 before 1.9.8-9778, 2.0.0 before 2.0.0-9779, and 2.1.0 before 2.1.0-9780 allows a remote attacker to include and display file content in an HTTP request via the CMON API.