CWE-36— Absolute Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.— MITRE CWE catalog
145 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-36page 3 of 3
- CVE-2024-8778MEDIUMCVSS 6.5EG 6.52024-09-16
OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attackers with regular privileges to read arbitrary system files.
- CVE-2024-7323MEDIUMCVSS 6.5EG 6.52024-08-02
Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately filter user input. A remote attacker with regular privilege can exploit this vulnerability to download arbitrary files fr…
- CVE-2023-41830MEDIUMCVSS 6.5EG 6.52024-05-03
An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.
- CVE-2023-30970MEDIUMCVSS 6.5EG 6.52024-01-29
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
- CVE-2023-34135MEDIUMCVSS 6.5EG 6.52023-07-13
Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file system via web service. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: …
- CVE-2022-20791MEDIUMCVSS 6.5EG 6.52022-07-06
A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Prese…
- CVE-2021-1617MEDIUMCVSS 6.5EG 6.52021-07-22
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnera…
- CVE-2021-32507MEDIUMCVSS 6.5EG 6.52021-07-07
Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of…
- CVE-2021-32506MEDIUMCVSS 6.5EG 6.52021-07-07
Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSA…
- CVE-2021-30173MEDIUMCVSS 6.5EG 6.52021-05-07
Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file.
- CVE-2023-2101MEDIUMCVSS 4.3EG 6.52023-04-15
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument url…
- CVE-2025-53651MEDIUMCVSS 6.3EG 6.32025-07-09
Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the Jenkins controller file system in the bui…
- CVE-2024-45291MEDIUMCVSS 6.3EG 6.32024-10-07
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links images from arbitrary paths. When embedding images has been enabled in HTML writer with `$wr…
- CVE-2023-5115MEDIUMCVSS 6.3EG 6.32023-12-18
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extr…
- CVE-2026-58300MEDIUMCVSS 6.2EG 6.22026-07-03
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
- CVE-2024-13945MEDIUMCVSS 6.0EG 6.02025-05-23
Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.…
- CVE-2026-47630MEDIUMCVSS 5.5EG 5.52026-08-18
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution.
- CVE-2021-34711MEDIUMCVSS 5.5EG 5.52021-10-06
A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit th…
- CVE-2026-15302MEDIUMCVSS 5.3EG 5.32026-07-10
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain file…
- CVE-2026-10075MEDIUMCVSS 5.3EG 5.32026-05-29
DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability.
- CVE-2026-44029MEDIUMCVSS 5.3EG 5.32026-05-05
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.…
- CVE-2026-7217MEDIUMCVSS 5.3EG 5.32026-04-28
A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read_docx/read_xlsx/read_pptx/list_xlsx_sheets/read_pdf of the file packages/mcp-office/src/index.ts of the component Docum…
- CVE-2024-10047MEDIUMCVSS 5.3EG 5.32025-03-20
parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.
- CVE-2024-6097MEDIUMCVSS 5.3EG 5.32025-02-12
In Progress® Telerik® Reporting versions prior to 2025 Q1 (19.0.25.211), information disclosure is possible by a local threat actor through an absolute path vulnerability.
- CVE-2023-5390MEDIUMCVSS 5.3EG 5.32024-01-31
An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limi…
- CVE-2025-53392MEDIUMCVSS 5.0EG 5.02025-06-28
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privileg…
- CVE-2024-57966MEDIUMCVSS 5.0EG 5.02025-02-03
libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
- CVE-2025-14253MEDIUMCVSS 4.9EG 4.92025-12-08
Vitals ESP developed by Galaxy Software Services has an Arbitrary File Read vulnerability, allowing privileged remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
- CVE-2025-9516MEDIUMCVSS 4.9EG 4.92025-09-04
The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 via the 'custom_log' parameter. This makes it possible for authenticated attackers, with Administrator-level access and a…
- CVE-2025-53079MEDIUMCVSS 4.9EG 4.92025-07-29
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
- CVE-2025-8009MEDIUMCVSS 4.9EG 4.92025-07-24
The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated …
- CVE-2024-10651MEDIUMCVSS 4.9EG 4.92024-11-01
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system fi…
- CVE-2026-6418MEDIUMCVSS 4.6EG 4.92026-05-05
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application allows administrative users to configure a source path for account data synchronization. Due to a lack of proper pa…
- CVE-2026-20834MEDIUMCVSS 4.6EG 4.62026-01-13
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
- CVE-2025-67898MEDIUMCVSS 4.5EG 4.52025-12-14
MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.
- CVE-2026-32175MEDIUMCVSS 4.3EG 4.32026-05-12
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. …
- CVE-2025-15237MEDIUMCVSS 4.3EG 4.32026-01-05
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerabilit…
- CVE-2025-15236MEDIUMCVSS 4.3EG 4.32026-01-05
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerabilit…
- CVE-2025-14848MEDIUMCVSS 4.3EG 4.32025-12-18
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
- CVE-2023-2765MEDIUMCVSS 4.3EG 4.32023-05-17
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path tr…
- CVE-2024-56321LOWCVSS 3.8EG 3.82025-01-03
GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to potentially execute arbitrary scripts on the hosting server or con…
- CVE-2025-70820LOWCVSS 3.5EG 3.52026-09-13
Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
- CVE-2024-1703LOWCVSS 3.5EG 3.52024-02-21
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit ha…
- CVE-2023-1176LOWCVSS 3.3EG 3.32023-03-24
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
- CVE-2023-50955LOWCVSS 2.4EG 2.42024-02-21
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.
Map vulnerabilities like CWE-36 to your infrastructure
EchelonGraph correlates every CVE — across CWE-36 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →