Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-22 · Path traversalDefinition on MITRE ↗Clear

77 results·Page 1 / 2

CVE-2026-59310
2026-08-18
Broadcom VMware vCenter Path Traversal Vulnerability
Broadcom

Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.

CWE-22 · Path traversal
Refssupport.broadcom.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-21
CVE-2026-48282
2026-07-07
Adobe ColdFusion Path Traversal Vulnerability
Adobe

Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.

CWE-22 · Path traversal
Refshelpx.adobe.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-10
CVE-2026-34909
2026-06-23
Ubiquiti UniFi OS Path Traversal Vulnerability
Ubiquiti

Ubiquiti UniFi OS contains a path traversal vulnerability which could allow a malicious actor with access to the network to access files on the underlying system that could be manipulated to access an underlying account.

CWE-22 · Path traversal
Refscommunity.ui.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-26
CVE-2026-20262
2026-06-15
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
Cisco

Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.

CWE-22 · Path traversal
Refssec.cloudapps.cisco.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-29
CVE-2024-1708
2026-04-28
ConnectWise ScreenConnect Path Traversal VulnerabilityRansomware
ConnectWise

ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.

CWE-22 · Path traversal
Refsconnectwise.comnvd.nist.gov
Federal remediation due 2026-05-12
CVE-2024-7399
2026-04-24
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung

Samsung MagicINFO 9 Server contains a path traversal vulnerability that could allow an attacker to write arbitrary files as system authority.

CWE-22 · Path traversalCWE-434 · Unrestricted file upload
Refssecurity.samsungtv.comnvd.nist.gov
Federal remediation due 2026-05-08
CVE-2024-57728
2026-04-24
SimpleHelp Path Traversal VulnerabilityRansomware
SimpleHelp

SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user.

CWE-22 · Path traversal
Refssimple-help.comnvd.nist.gov
Federal remediation due 2026-05-08
CVE-2025-2749
2026-04-20
Kentico Xperience Path Traversal Vulnerability
Kentico

Kentico Xperience contains a path traversal vulnerability that could allow an authenticated user's Staging Sync Server to upload arbitrary data to path relative locations.

CWE-22 · Path traversalCWE-434 · Unrestricted file upload
Refsdevnet.kentico.comnvd.nist.gov
Federal remediation due 2026-05-04
CVE-2025-8110
2026-01-12
Gogs Path Traversal Vulnerability
Gogs

Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.

CWE-22 · Path traversal
Refsgithub.comnvd.nist.gov
Federal remediation due 2026-02-02
CVE-2025-6218
2025-12-09
RARLAB WinRAR Path Traversal Vulnerability
RARLAB

RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.

CWE-22 · Path traversal
Refswin-rar.comnvd.nist.gov
Federal remediation due 2025-12-30
CVE-2021-43798
2025-10-09
Grafana Path Traversal Vulnerability
Grafana Labs

Grafana contains a path traversal vulnerability that could allow access to local files.

CWE-22 · Path traversal
Refsgrafana.comnvd.nist.gov
Federal remediation due 2025-10-30
CVE-2019-5418
2025-07-07
Rails Ruby on Rails Path Traversal Vulnerability
Rails

Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents.

CWE-22 · Path traversal
Refsweb.archive.orgnvd.nist.gov
Federal remediation due 2025-07-28
CVE-2024-0769
2025-06-25
D-Link DIR-859 Router Path Traversal Vulnerability
D-Link

D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml allows for the leakage of session data potentially enabling privilege escalation and unauthorized control of the device. This vulnerability affects legacy D-Link products. All associated hardware revisions have reached their end-of-life (EOL) or end-of-service (EOS) life cycle and should be retired and replaced per vendor instructions.

CWE-22 · Path traversal
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2025-07-16
CVE-2025-4632
2025-05-22
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Samsung

Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.

CWE-22 · Path traversal
Refssecurity.samsungtv.comnvd.nist.gov
Federal remediation due 2025-06-12
CVE-2025-27920
2025-05-19
Srimax Output Messenger Directory Traversal Vulnerability
Srimax

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

CWE-22 · Path traversal
Refsoutputmessenger.comnvd.nist.gov
Federal remediation due 2025-06-09
CVE-2023-38950
2025-05-19
ZKTeco BioTime Path Traversal Vulnerability
ZKTeco

ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.

CWE-22 · Path traversal
Refszkteco.comnvd.nist.gov
Federal remediation due 2025-06-09
CVE-2025-34028
2025-05-02
Commvault Command Center Path Traversal Vulnerability
Commvault

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

CWE-22 · Path traversal
Refsdocumentation.commvault.comnvd.nist.gov
Federal remediation due 2025-05-23
CVE-2017-12637
2025-03-19
SAP NetWeaver Directory Traversal Vulnerability
SAP

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

CWE-22 · Path traversal
RefsSAP users must have an account to log in and access the patchnvd.nist.gov
Federal remediation due 2025-04-09
CVE-2024-4885
2025-03-03
Progress WhatsUp Gold Path Traversal Vulnerability
Progress

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

CWE-22 · Path traversal
Refscommunity.progress.comnvd.nist.gov
Federal remediation due 2025-03-24
CVE-2024-57727
2025-02-13
SimpleHelp Path Traversal VulnerabilityRansomware
SimpleHelp

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords.

CWE-22 · Path traversal
Refssimple-help.comAdditional CISA Mitigation Instructionsnvd.nist.gov
Federal remediation due 2025-03-06
CVE-2024-55550
2025-01-07
Mitel MiCollab Path Traversal VulnerabilityRansomware
Mitel

Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input sanitization. This vulnerability can be chained with CVE-2024-41713, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

CWE-22 · Path traversal
Refsmitel.comnvd.nist.gov
Federal remediation due 2025-01-28
CVE-2024-41713
2025-01-07
Mitel MiCollab Path Traversal VulnerabilityRansomware
Mitel

Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allows an unauthenticated, remote attacker to read arbitrary files on the server.

CWE-22 · Path traversal
Refsmitel.comnvd.nist.gov
Federal remediation due 2025-01-28
CVE-2024-11667
2024-12-03
Zyxel Multiple Firewalls Path Traversal VulnerabilityRansomware
Zyxel

Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.

CWE-22 · Path traversal
Refszyxel.comnvd.nist.gov
Federal remediation due 2024-12-24
CVE-2021-26086
2024-11-12
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Atlassian

Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.

CWE-22 · Path traversal
Refsjira.atlassian.comnvd.nist.gov
Federal remediation due 2024-12-03
CVE-2019-16278
2024-11-07
Nostromo nhttpd Directory Traversal Vulnerability
Nostromo

Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.

CWE-22 · Path traversal
Refsnazgul.chnvd.nist.gov
Federal remediation due 2024-11-28
CVE-2024-8963
2024-09-19
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
Ivanti

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.

CWE-22 · Path traversal
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-10-10
CVE-2024-7262
2024-09-03
Kingsoft WPS Office Path Traversal Vulnerability
Kingsoft

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2024-09-24
CVE-2021-20124
2024-09-03
Draytek VigorConnect Path Traversal Vulnerability
DrayTek

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CWE-22 · Path traversal
Refsdraytek.comnvd.nist.gov
Federal remediation due 2024-09-24
CVE-2021-20123
2024-09-03
Draytek VigorConnect Path Traversal Vulnerability
DrayTek

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

CWE-22 · Path traversal
Refsdraytek.comnvd.nist.gov
Federal remediation due 2024-09-24
CVE-2024-32113
2024-08-07
Apache OFBiz Path Traversal Vulnerability
Apache

Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.

CWE-22 · Path traversal
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-08-28
CVE-2024-28995
2024-07-17
SolarWinds Serv-U Path Traversal Vulnerability
SolarWinds

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

CWE-22 · Path traversal
Refssolarwinds.comnvd.nist.gov
Federal remediation due 2024-08-07
CVE-2023-47246
2023-11-13
SysAid Server Path Traversal VulnerabilityRansomware
SysAid

SysAid Server (on-premises version) contains a path traversal vulnerability that leads to code execution.

CWE-22 · Path traversal
Refssysaid.comnvd.nist.gov
Federal remediation due 2023-12-04
CVE-2023-32315
2023-08-24
Ignite Realtime Openfire Path Traversal Vulnerability
Ignite Realtime

Ignite Realtime Openfire contains a path traversal vulnerability that allows an unauthenticated attacker to access restricted pages in the Openfire Admin Console reserved for administrative users.

CWE-22 · Path traversal
Refsigniterealtime.orgnvd.nist.gov
Federal remediation due 2023-09-14
CVE-2023-35081
2023-07-31
Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
Ivanti

Ivanti Endpoint Manager Mobile (EPMM) contains a path traversal vulnerability that enables an authenticated administrator to perform malicious file writes to the EPMM server. This vulnerability can be used in conjunction with CVE-2023-35078 to bypass authentication and ACLs restrictions (if applicable).

CWE-22 · Path traversal
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2023-08-21
CVE-2022-41328
2023-03-14
Fortinet FortiOS Path Traversal Vulnerability
Fortinet

Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.

CWE-22 · Path traversal
Refsfortiguard.comnvd.nist.gov
Federal remediation due 2023-04-04
CVE-2018-5430
2022-12-29
TIBCO JasperReports Server Information Disclosure Vulnerability
TIBCO

TIBCO JasperReports Server contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files.

CWE-22 · Path traversal
Refstibco.comnvd.nist.gov
Federal remediation due 2023-01-19
CVE-2018-18809
2022-12-29
TIBCO JasperReports Library Directory Traversal Vulnerability
TIBCO

TIBCO JasperReports Library contains a directory-traversal vulnerability that may allow web server users to access contents of the host system.

CWE-22 · Path traversal
Refstibco.comnvd.nist.gov
Federal remediation due 2023-01-19
CVE-2022-26500
2022-12-13
Veeam Backup & Replication Remote Code Execution VulnerabilityRansomware
Veeam

The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access internal API functions. A remote attacker can send input to the internal API which may lead to uploading and executing of malicious code.

CWE-22 · Path traversal
Refsveeam.comnvd.nist.gov
Federal remediation due 2023-01-03
CVE-2022-41352
2022-10-20
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
Synacor

Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.

CWE-22 · Path traversal
Refswiki.zimbra.comnvd.nist.gov
Federal remediation due 2022-11-10
CVE-2022-26352
2022-08-25
dotCMS Unrestricted Upload of File VulnerabilityRansomware
dotCMS

dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows for directory traversal, in which the file is saved outside of the intended storage location. Exploitation allows for remote code execution.

CWE-22 · Path traversalCWE-138
Refsdotcms.comnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2020-36193
2022-08-25
PEAR Archive_Tar Improper Link Resolution Vulnerability
PEAR

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

CWE-22 · Path traversalCWE-59 · Link following
Refsgithub.comnvd.nist.gov
Federal remediation due 2022-09-15
CVE-2022-27925
2022-08-11
Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload VulnerabilityRansomware
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

CWE-22 · Path traversal
Refsblog.zimbra.comnvd.nist.gov
Federal remediation due 2022-09-01
CVE-2022-30333
2022-08-09
RARLAB UnRAR Directory Traversal VulnerabilityRansomware
RARLAB

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

CWE-22 · Path traversalCWE-59 · Link following
RefsVulnerability updated with version 6.12. Accessing link will download update informationnvd.nist.gov
Federal remediation due 2022-08-30
CVE-2019-7195
2022-06-08
QNAP Photo Station Path Traversal VulnerabilityRansomware
QNAP

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2019-7194
2022-06-08
QNAP Photo Station Path Traversal VulnerabilityRansomware
QNAP

QNAP devices running Photo Station contain an external control of file name or path vulnerability allowing remote attackers to access or modify system files.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-22
CVE-2015-0016
2022-05-25
Microsoft Windows TS WebProxy Directory Traversal Vulnerability
Microsoft

Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-15
CVE-2022-29464
2022-04-25
WSO2 Multiple Products Unrestrictive Upload of File VulnerabilityRansomware
WSO2

Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-16
CVE-2014-0780
2022-04-15
InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
InduSoft

InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowing for remote code execution.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-05-06
CVE-2019-7483
2022-03-28
SonicWall SMA100 Directory Traversal Vulnerability
SonicWall

In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.

CWE-22 · Path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-18
CVE-2020-1631
2022-03-25
Juniper Junos OS Path Traversal Vulnerability
Juniper

A path traversal vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform remote code execution.

CWE-22 · Path traversalCWE-73
Refsnvd.nist.gov
Federal remediation due 2022-04-15
Prev1 / 2Next