CWE-23— Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.— MITRE CWE catalog
523 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-23page 9 of 11
- CVE-2020-8865MEDIUMCVSS 6.3EG 6.32020-03-23
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentication is required to exploit this vulnerability. The specific flaw exists within edit.php. …
- CVE-2026-58413MEDIUMCVSS 6.1EG 6.12026-07-20
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, backupId)` computes the backup path with `join(envDir, '.backups', backupId)` and only checks that this path exists. It …
- CVE-2025-53082MEDIUMCVSS 6.1EG 6.12025-07-29
An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unintended locations on the filesystem. Exploitation is restricted to specific, authorized private IP addresses.
- CVE-2024-20310MEDIUMCVSS 6.1EG 6.12024-04-03
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against an authentica…
- CVE-2023-27993MEDIUMCVSS 6.0EG 6.02023-05-03
A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system via crafted CLI commands.
- CVE-2026-24909MEDIUMCVSS 5.9EG 5.92026-01-27
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
- CVE-2018-18990MEDIUMCVSS 5.3EG 5.92019-02-05
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server proc…
- CVE-2025-64714MEDIUMCVSS 5.8EG 5.82025-11-13
PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior to version 2.0.3, an unauthenticated Local File Inclusion exists in the template-switching feature. If `templateselect…
- CVE-2025-49466MEDIUMCVSS 5.8EG 5.82025-06-05
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,
- CVE-2022-23531MEDIUMCVSS 5.8EG 5.82022-12-17
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to 0.1.5 are vulnerable to Relative Path Traversal when scanning a specially-crafted local PyPI package. Running GuardDog against a specially-crafted package can al…
- CVE-2025-24819MEDIUMCVSS 5.7EG 5.72026-04-07
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.
- CVE-2024-25944MEDIUMCVSS 5.7EG 5.72024-03-29
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesyste…
- CVE-2018-5448MEDIUMCVSS 4.8EG 5.72018-05-04
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.
- CVE-2020-5284MEDIUMCVSS 4.4EG 5.62020-03-30
Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the…
- CVE-2026-60093MEDIUMCVSS 5.5EG 5.52026-08-24
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake …
- CVE-2026-21082MEDIUMCVSS 5.5EG 5.52026-08-10
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
- CVE-2026-15415MEDIUMCVSS 5.5EG 5.52026-07-17
AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. …
- CVE-2026-41612MEDIUMCVSS 5.5EG 5.52026-05-12
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
- CVE-2025-13199MEDIUMCVSS 5.5EG 5.52025-11-15
A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible …
- CVE-2025-59456MEDIUMCVSS 5.5EG 5.52025-09-17
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
- CVE-2024-46664MEDIUMCVSS 5.5EG 5.52025-01-14
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
- CVE-2024-32115MEDIUMCVSS 5.5EG 5.52025-01-14
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
- CVE-2024-43614MEDIUMCVSS 5.5EG 5.52024-10-08
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
- CVE-2023-23391MEDIUMCVSS 5.5EG 5.52023-03-14
Office for Android Spoofing Vulnerability
- CVE-2023-20040MEDIUMCVSS 5.5EG 5.52023-01-20
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vu…
- CVE-2022-34378MEDIUMCVSS 5.5EG 5.52022-09-02
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to d…
- CVE-2020-1904MEDIUMCVSS 5.5EG 5.52020-10-06
A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachm…
- CVE-2019-0074MEDIUMCVSS 5.5EG 5.52019-10-09
A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with Next-Generation Routing Engine (NG-RE) allows a local authenticated user to read sensitive system files. This issue onl…
- CVE-2026-59996MEDIUMCVSS 5.4EG 5.42026-07-08
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
- CVE-2026-59995MEDIUMCVSS 5.4EG 5.42026-07-08
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
- CVE-2025-24343MEDIUMCVSS 5.4EG 5.42025-04-30
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files in arbitrary file system paths via a crafted HTTP request.
- CVE-2025-43016MEDIUMCVSS 5.4EG 5.42025-04-25
In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session
- CVE-2025-1599MEDIUMCVSS 5.4EG 5.42025-02-24
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/app/profile_crud.php. The manipulation of the argume…
- CVE-2023-29189MEDIUMCVSS 5.4EG 5.42023-04-11
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is expos…
- CVE-2020-3597MEDIUMCVSS 5.4EG 5.42020-10-08
A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficien…
- CVE-2024-24942MEDIUMCVSS 5.3EG 5.42024-02-06
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
- CVE-2026-50024MEDIUMCVSS 5.3EG 5.32026-09-09
GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/,…
- CVE-2026-44948MEDIUMCVSS 5.3EG 5.32026-06-30
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.14.7 and 0.15.0 up to 0.15.3 could be used to traverse outside of the intended directory, c…
- CVE-2026-47680MEDIUMCVSS 5.3EG 5.32026-06-05
The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influe…
- CVE-2025-40605MEDIUMCVSS 5.3EG 5.32025-11-20
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories out…
- CVE-2025-58752MEDIUMCVSS 5.3EG 5.32025-09-08
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, any HTML files on the machine were served regardless of the `server.fs` settings. Only apps that explicitly expose the Vite dev server …
- CVE-2025-55202MEDIUMCVSS 5.3EG 5.32025-08-29
Opencast is a free, open-source platform to support the management of educational audio and video content. In version 18.0 and versions before 17.7, the protections against path traversal attacks in the UI config module are insufficient, s…
- CVE-2025-8464MEDIUMCVSS 5.3EG 5.32025-08-16
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticate…
- CVE-2025-22859MEDIUMCVSS 5.3EG 5.32025-05-13
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via up…
- CVE-2024-6483MEDIUMCVSS 5.3EG 5.32025-03-20
A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names…
- CVE-2024-8510MEDIUMCVSS 5.3EG 5.32025-03-17
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
- CVE-2025-1086MEDIUMCVSS 5.3EG 5.32025-02-07
A vulnerability has been found in Safetytest Cloud-Master Server up to 1.1.1 and classified as critical. This vulnerability affects unknown code of the file /static/. The manipulation leads to path traversal: '../filedir'. The attack can b…
- CVE-2025-0390MEDIUMCVSS 5.3EG 5.32025-01-11
A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. The manipulation leads to path traversal: '../…
- CVE-2024-9405MEDIUMCVSS 5.3EG 5.32024-10-01
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of…
- CVE-2024-24938MEDIUMCVSS 5.3EG 5.32024-02-06
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
Map vulnerabilities like CWE-23 to your infrastructure
EchelonGraph correlates every CVE — across CWE-23 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →