CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 11 of 11
- CVE-2025-55013MEDIUMCVSS 4.2EG 4.22025-08-09
The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task_handler.py) accepts a SHA-256 value re…
- CVE-2023-49801MEDIUMCVSS 4.2EG 4.22024-01-12
Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issue relates to the `get_pfp` and `get_banner` routes on Auth Server. The issue is that there is no check to ensure that t…
- CVE-2025-66386MEDIUMCVSS 4.1EG 4.12025-11-28
app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin.
- CVE-2024-37138MEDIUMCVSS 4.1EG 4.12024-06-26
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to the …
- CVE-2025-60023MEDIUMCVSS 4.0EG 4.02025-10-23
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and delete arbitrary…
- CVE-2025-59776MEDIUMCVSS 4.0EG 4.02025-10-23
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerability allows an unauthenticated remote attacker to interact with the ProductivityService PLC simulator and create arbitrary…
- CVE-2024-4330MEDIUMCVSS 3.3EG 4.02024-05-30
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities' endpoint. By craft…
- CVE-2025-22873LOWCVSS 3.8EG 3.82026-02-04
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory…
- CVE-2022-2106LOWCVSS 3.8EG 3.82022-06-27
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files.
- CVE-2025-64757LOWCVSS 3.5EG 3.52025-11-19
Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbitrary local file read access through the image optimization endpoint. The vulnerability affe…
- CVE-2023-35816LOWCVSS 3.5EG 3.52025-04-28
DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
- CVE-2023-32778LOWCVSS 3.3EG 3.32026-09-14
An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.
- CVE-2025-62187LOWCVSS 3.3EG 3.32025-10-07
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations on Windows and Linux (media file pathnames are not necessarily relative to the media folder).
- CVE-2024-22226LOWCVSS 3.3EG 3.32024-02-12
Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, to gain unauthorized write access to the files stored on t…
- CVE-2023-34117LOWCVSS 3.3EG 3.32023-07-11
Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable information disclosure via local access.
- CVE-2022-4123LOWCVSS 3.3EG 3.32022-12-08
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.
- CVE-2025-59682LOWCVSS 3.1EG 3.12025-10-01
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by the "startapp --template" and "startproject --template" commands, allows partial directory t…
- CVE-2026-1762LOWCVSS 2.9EG 2.92026-02-10
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
- CVE-2024-24940LOWCVSS 2.8EG 2.82024-02-06
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
- CVE-2026-8387LOWCVSS 2.4EG 2.42026-07-01
A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extracting `.zip` archives using the `ZipFile.extractall()` method in `StorageManager._extract_to_cache()`. This issue arises …
- CVE-2026-45188LOWCVSS 2.4EG 2.42026-06-25
Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0, which fixes the issue.
- CVE-2026-21620LOWCVSS 2.3EG 2.32026-02-20
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This …
- CVE-2024-35274LOWCVSS 2.3EG 2.32024-11-12
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version …
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →