CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 1 of 11
- CVE-2025-64446CRITICALCVSS 9.8EG 9.8⚠ KEV2025-11-14
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute adm…
- CVE-2021-40870CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-13
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute arbitrary code via directory traversal.
- CVE-2020-5410CRITICALCVSS 7.5EG 9.0⚠ KEV2020-06-02
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or…
- CVE-2024-27199CRITICALCVSS 7.3EG 9.0⚠ KEV2024-03-04
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- CVE-2026-34926CRITICALCVSS 6.7EG 9.0⚠ KEV2026-05-21
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations. This vuln…
- CVE-2026-52813CRITICALCVSS 10.0EG 10.02026-06-23
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths following these path traversals. This allo…
- CVE-2026-8326CRITICALCVSS 10.0EG 10.02026-05-29
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component is the RDP drive redirection. Dependi…
- CVE-2026-33494CRITICALCVSS 10.0EG 10.02026-03-26
ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based on sets of Access Rules. Versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal. An …
- CVE-2023-3941CRITICALCVSS 10.0EG 10.02024-05-21
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR…
- CVE-2024-24578CRITICALCVSS 10.0EG 10.02024-03-18
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior to version 3.75.6.20240316 contains a unauthenticated remote code execution (RCE) vulnerability, caused by multiple iss…
- CVE-2026-66897CRITICALCVSS 9.9EG 9.92026-08-24
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions, or any user launching a crafted image, to overwrite arbitrary files on the host system as root. When processing target…
- CVE-2025-62878CRITICALCVSS 9.9EG 9.92026-02-25
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.
- CVE-2025-52207CRITICALCVSS 9.9EG 9.92025-06-27
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbitrary directory.
- CVE-2023-40714CRITICALCVSS 9.9EG 9.92025-04-02
A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements
- CVE-2024-3025CRITICALCVSS 9.9EG 9.92024-04-10
mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to refe…
- CVE-2023-6825CRITICALCVSS 9.9EG 9.92024-03-13
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and including version 7.2.1 (free version) and 8.3.4 (Pro version) via the target parameter in the mk_file_folder_manager…
- CVE-2023-37913CRITICALCVSS 9.9EG 9.92023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 3.5-milestone-1 and prior to versions 14.10.8 and 15.3-rc-1, triggering the office converter with a specially craf…
- CVE-2023-3701CRITICALCVSS 9.9EG 9.92023-10-04
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerability, an authenticated non privileged user could access/modify stored resources of other users. It could also be possible…
- CVE-2026-63509CRITICALCVSS 8.8EG 9.92026-08-20
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
- CVE-2026-76440CRITICALCVSS 9.8EG 9.82026-09-14
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review res…
- CVE-2026-16230CRITICALCVSS 9.8EG 9.82026-08-11
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthentica…
- CVE-2026-59792CRITICALCVSS 9.8EG 9.82026-07-10
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible
- CVE-2026-4415CRITICALCVSS 9.8EG 9.82026-03-30
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, le…
- CVE-2026-21659CRITICALCVSS 9.8EG 9.82026-02-27
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected dev…
- CVE-2024-47856CRITICALCVSS 9.8EG 9.82025-11-24
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher…
- CVE-2025-3365CRITICALCVSS 9.8EG 9.82025-06-06
A missing protection against path traversal allows to access any file on the server.
- CVE-2025-23410CRITICALCVSS 9.8EG 9.82025-03-05
When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and will not check for path traversal in supported archive types.
- CVE-2023-34990CRITICALCVSS 9.8EG 9.82024-12-18
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.
- CVE-2024-11315CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11314CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11313CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11312CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2024-11311CRITICALCVSS 9.8EG 9.82024-11-18
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to arbitrary code execution by uploa…
- CVE-2023-6307CRITICALCVSS 9.8EG 9.82023-11-27
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path …
- CVE-2023-4760CRITICALCVSS 9.8EG 9.82023-09-21
In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUp…
- CVE-2023-4897CRITICALCVSS 9.8EG 9.82023-09-11
Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
- CVE-2022-39345CRITICALCVSS 9.8EG 9.82022-10-25
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.…
- CVE-2022-28814CRITICALCVSS 9.8EG 9.82022-09-28
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of t…
- CVE-2020-27304CRITICALCVSS 9.8EG 9.82021-10-21
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file u…
- CVE-2020-8271CRITICALCVSS 9.8EG 9.82020-11-16
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
- CVE-2020-25172CRITICALCVSS 9.8EG 9.82020-11-06
A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers to upload or download arbitrary files.
- CVE-2019-17640CRITICALCVSS 9.8EG 9.82020-10-15
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Ope…
- CVE-2020-12006CRITICALCVSS 9.8EG 9.82020-05-08
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist that may allow a low privilege user to overwrite files outside the application’s control.
- CVE-2020-10631CRITICALCVSS 9.8EG 9.82020-04-09
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
- CVE-2017-9664CRITICALCVSS 9.8EG 9.82018-05-24
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring tools without any aut…
- CVE-2023-0511CRITICALCVSS 9.1EG 9.82023-02-28
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. This issue affects Access Management Java Policy Agent: all versions up to 5.10.1
- CVE-2023-0339CRITICALCVSS 9.1EG 9.82023-02-28
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This issue affects Access Management Web Policy Agent: all versions up to 5.10.1
- CVE-2020-25176CRITICALCVSS 9.1EG 9.82022-03-18
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved …
- CVE-2021-22650CRITICALCVSS 7.5EG 9.82022-07-28
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.
- CVE-2022-2120CRITICALCVSS 7.5EG 9.82022-06-24
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execut…
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →