CWE-36— Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.— MITRE CWE catalog
145 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-36page 1 of 3
- CVE-2024-13161CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-13160CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-13159CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-48248CRITICALCVSS 8.6EG 9.0⚠ KEV2025-03-04
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credenti…
- CVE-2018-20250CRITICALCVSS 7.8EG 9.0⚠ KEV2019-02-05
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extr…
- CVE-2026-57211CRITICALCVSS 10.0EG 10.02026-07-10
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path val…
- CVE-2024-51549CRITICALCVSS 10.0EG 10.02024-12-05
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2023-3765CRITICALCVSS 10.0EG 10.02023-07-19
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
- CVE-2026-68487CRITICALCVSS 9.9EG 9.92026-09-10
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
- CVE-2022-24877CRITICALCVSS 9.9EG 9.92022-05-06
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem …
- CVE-2025-34392CRITICALCVSS 9.8EG 9.82025-12-10
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by the application. This can lead to arbitrary file write and …
- CVE-2025-0851CRITICALCVSS 9.8EG 9.82025-01-29
A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad actor to write files to arbitrary locations.
- CVE-2024-10811CRITICALCVSS 9.8EG 9.82025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-9924CRITICALCVSS 9.8EG 9.82024-10-14
The fix for CVE-2024-26261 was incomplete, and and the specific package for OAKlouds from Hgiga remains at risk. Unauthenticated remote attackers still can download arbitrary system files, which may be deleted subsequently .
- CVE-2024-20401CRITICALCVSS 9.8EG 9.82024-07-17
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is …
- CVE-2026-47243CRITICALCVSS 9.2EG 9.22026-05-27
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to …
- CVE-2026-89009CRITICALCVSS 9.1EG 9.12026-09-11
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the …
- CVE-2026-47606CRITICALCVSS 9.1EG 9.12026-08-18
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.
- CVE-2025-68472CRITICALCVSS 9.1EG 9.12026-01-12
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move th…
- CVE-2024-10833CRITICALCVSS 9.1EG 9.12025-03-20
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary…
- CVE-2024-10831CRITICALCVSS 9.1EG 9.12025-03-20
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises …
- CVE-2024-47883CRITICALCVSS 9.1EG 9.12024-10-24
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class to refer to (what are expected to be) local resource files, like images or templates. This…
- CVE-2024-2362CRITICALCVSS 9.1EG 9.12024-06-06
A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this vulnerability to delete a…
- CVE-2025-7846HIGHCVSS 8.8EG 8.82025-10-31
The WordPress User Extra Fields plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the save_fields() function in all versions up to, and including, 16.7. This makes it possible for aut…
- CVE-2025-57790HIGHCVSS 8.8EG 8.82025-08-20
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to remote code execution.
- CVE-2025-6381HIGHCVSS 8.8EG 8.82025-06-28
The BeeTeam368 Extensions plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.4 via the handle_remove_temp_file() function. This makes it possible for authenticated attackers, with Subscriber…
- CVE-2024-8501HIGHCVSS 8.8EG 8.82025-03-20
An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting the download_file me…
- CVE-2024-29053HIGHCVSS 8.8EG 8.82024-04-09
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2024-21323HIGHCVSS 8.8EG 8.82024-04-09
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2023-5022HIGHCVSS 8.8EG 8.82023-09-17
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepat…
- CVE-2022-20958HIGHCVSS 8.3EG 8.82022-11-04
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerabi…
- CVE-2026-82092HIGHCVSS 6.5EG 8.82026-09-10
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
- CVE-2026-32997HIGHCVSS 8.6EG 8.62026-05-28
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-based Veeam Backup & Replication server.
- CVE-2024-33620HIGHCVSS 8.6EG 8.62024-06-18
Absolute path traversal vulnerability exists in ID Link Manager and FUJITSU Software TIME CREATOR. If this vulnerability is exploited, the file contents including sensitive information on the server may be retrieved by an unauthenticated r…
- CVE-2026-54202HIGHCVSS 8.5EG 8.52026-08-07
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation functionality. Because the archive path is user-controlled and insufficiently validated, an attacker can manipulate the in…
- CVE-2026-55062HIGHCVSS 8.4EG 8.42026-08-17
uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory compon…
- CVE-2026-46345HIGHCVSS 8.4EG 8.42026-05-28
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does no…
- CVE-2026-26337HIGHCVSS 8.2EG 8.22026-02-19
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-side request forgery through the absolute path traversal.
- CVE-2025-36574HIGHCVSS 8.2EG 8.22025-06-10
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Una…
- CVE-2026-42315HIGHCVSS 8.1EG 8.12026-05-11
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_folder", there is no sanitization at all…
- CVE-2025-13282HIGHCVSS 8.1EG 8.12025-11-17
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in…
- CVE-2024-12646HIGHCVSS 8.1EG 8.12024-12-16
The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs…
- CVE-2024-12643HIGHCVSS 8.1EG 8.12024-12-16
The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs,…
- CVE-2021-21586HIGHCVSS 8.1EG 8.12021-07-15
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.
- CVE-2025-36357HIGHCVSS 8.0EG 8.02025-11-17
IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing absolute path sequences to view, read, or wr…
- CVE-2026-68896HIGHCVSS 7.8EG 7.82026-09-08
Absolute path traversal in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
- CVE-2026-69612HIGHCVSS 7.8EG 7.82026-09-08
Absolute path traversal in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
- CVE-2023-40597HIGHCVSS 7.8EG 7.82023-08-30
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
- CVE-2025-46822HIGHCVSS 7.7EG 7.72025-05-21
OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path trav…
- CVE-2024-45290HIGHCVSS 7.7EG 7.72024-10-07
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file which links media from external URLs. When opening the XLSX file, PhpSpreadsheet retrieves the image si…
Map vulnerabilities like CWE-36 to your infrastructure
EchelonGraph correlates every CVE — across CWE-36 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →