CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 4 of 11
- CVE-2022-34836HIGHCVSS 5.9EG 8.22022-08-24
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability coul…
- CVE-2026-82765HIGHCVSS 8.1EG 8.12026-09-14
Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
- CVE-2026-82768HIGHCVSS 8.1EG 8.12026-09-14
Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.
- CVE-2026-80133HIGHCVSS 8.1EG 8.12026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this …
- CVE-2026-66881HIGHCVSS 8.1EG 8.12026-08-05
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry ca…
- CVE-2026-15802HIGHCVSS 8.1EG 8.12026-07-22
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possi…
- CVE-2026-48681HIGHCVSS 8.1EG 8.12026-06-04
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
- CVE-2026-5422HIGHCVSS 8.1EG 8.12026-06-02
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check in the _get_os_path() function within jupyter_server/services/contents/fileio.py. The check uses startswith(root) with…
- CVE-2026-5966HIGHCVSS 8.1EG 8.12026-04-20
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attackers with web access can exploit Path Traversal to delete arbitrary files on the system.
- CVE-2026-26362HIGHCVSS 8.1EG 8.12026-02-19
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized modification of critical s…
- CVE-2025-32409HIGHCVSS 8.1EG 8.12025-04-07
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signed with debug keys) can be sent to TCP port 60002, and placed into the correct image-update location as a consequence of…
- CVE-2025-2007HIGHCVSS 8.1EG 8.12025-04-01
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteImage() function in all versions up to, and including, 7.19. This makes it…
- CVE-2024-12642HIGHCVSS 8.1EG 8.12024-12-16
TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the AP…
- CVE-2024-0549HIGHCVSS 8.1EG 8.12024-04-16
mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythin…
- CVE-2023-42456HIGHCVSS 8.1EG 8.12023-09-21
Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo attempt, but instead only requiring authentication every once in a while in every terminal or process group. Only once a c…
- CVE-2022-21177HIGHCVSS 8.1EG 8.12022-03-11
There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products: CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00 to R4.03.00, from R5.01.00 to R5.…
- CVE-2021-41242HIGHCVSS 8.1EG 8.12021-12-10
OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 15.5.12 and 16.0.5. By providing a filename that contains a relative path as a parameter in some REST methods, it is pos…
- CVE-2020-7377HIGHCVSS 8.1EG 8.12020-08-24
The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the…
- CVE-2019-3943HIGHCVSS 8.1EG 8.12019-04-10
MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote a…
- CVE-2018-10615HIGHCVSS 8.1EG 8.12018-06-04
Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform.
- CVE-2020-17518HIGHCVSS 7.5EG 8.12021-01-05
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Fl…
- CVE-2023-1045HIGHCVSS 3.8EG 8.12023-02-26
A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin.php/accessory/filesdel.html. The manipulation of the argument filedelur leads to relative p…
- CVE-2026-40400HIGHCVSS 8.0EG 8.02026-07-14
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
- CVE-2026-14476HIGHCVSS 8.0EG 8.02026-07-07
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files …
- CVE-2025-53829HIGHCVSS 8.0EG 8.02026-07-06
ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privileges can exploit a path traversal vulnerability in the system to execute arbitrary code. U…
- CVE-2026-33435HIGHCVSS 8.0EG 8.02026-04-15
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in…
- CVE-2024-54154HIGHCVSS 8.0EG 8.02024-12-04
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
- CVE-2024-45731HIGHCVSS 8.0EG 8.02024-10-14
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in …
- CVE-2024-43399HIGHCVSS 8.0EG 8.02024-08-19
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis section. Specifically,…
- CVE-2021-43555HIGHCVSS 7.3EG 8.02021-11-19
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the…
- CVE-2024-2053HIGHCVSS 7.5EG 7.92024-03-21
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The…
- CVE-2022-23854HIGHCVSS 7.5EG 7.92022-12-23
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.
- CVE-2026-72948HIGHCVSS 7.8EG 7.82026-09-08
Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally.
- CVE-2026-65810HIGHCVSS 7.8EG 7.82026-08-11
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- CVE-2026-50454HIGHCVSS 7.8EG 7.82026-07-14
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
- CVE-2025-41280HIGHCVSS 7.8EG 7.82026-05-29
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector …
- CVE-2025-62552HIGHCVSS 7.8EG 7.82025-12-09
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- CVE-2025-10203HIGHCVSS 7.8EG 7.82025-09-15
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK fil…
- CVE-2023-50255HIGHCVSS 7.8EG 7.82023-12-27
Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerability in deepin-compressor that can be exploited to achieve Remote Command Execution on the target system upon opening …
- CVE-2023-35359HIGHCVSS 7.8EG 7.82023-08-08
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2023-34394HIGHCVSS 7.8EG 7.82023-07-19
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local priv…
- CVE-2022-42470HIGHCVSS 7.8EG 7.82023-04-11
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specifi…
- CVE-2023-23379HIGHCVSS 7.8EG 7.82023-02-14
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- CVE-2021-29100HIGHCVSS 7.8EG 7.82021-05-05
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code exec…
- CVE-2023-30630HIGHCVSS 7.1EG 7.82023-04-13
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately add…
- CVE-2026-15913HIGHCVSS 7.7EG 7.72026-09-09
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, ac…
- CVE-2026-54910HIGHCVSS 7.7EG 7.72026-07-20
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which ar…
- CVE-2026-59832HIGHCVSS 7.7EG 7.72026-07-09
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler serveSnippets in kernel/server/serve.go joins a single-decoded request path with the snippets directory without subpath co…
- CVE-2025-59341HIGHCVSS 7.7EG 7.72025-09-17
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion (LFI) issue was identified in the esm.sh service URL handling. An attacker could craft a request that causes the serve…
- CVE-2025-54531HIGHCVSS 7.7EG 7.72025-07-28
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →