CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

391 vulnerabilities with CWE-23
CVE-2024-24940 LOW
JetBrains IntelliJ IDEA <2023.3.3 - Path Traversal
CVSS 2.8
CVE-2024-24938 MEDIUM
JetBrains TeamCity <2023.11.2 - Path Traversal
CVSS 5.3
CVE-2024-22096 MEDIUM
Rapid SCADA <5.8.4 - Path Traversal
CVSS 6.5
CVE-2024-22421 HIGH
JupyterLab <4.1.0b2-3.6.7 - Info Disclosure
CVSS 7.6
CVE-2024-22415 HIGH
jupyter-lsp - Privilege Escalation
CVSS 7.3
CVE-2023-35816 LOW
DevExpress <23.1.3 - Code Injection
CVSS 3.5
CVE-2023-40714 CRITICAL
Fortinet FortiSIEM <6.7.2-6.6.3 - Path Traversal
CVSS 9.9
CVE-2023-34990 CRITICAL
Fortinet Fortiwlm < 8.5.5 - Code Injection
CVSS 9.8
CVE-2023-3941 CRITICAL
ZkTeco-based OEM devices <1.8.25-7354-Ver1.0.0 - Path Traversal
CVSS 10.0
CVE-2023-3940 HIGH
ZkTeco-based OEM devices <1.8.25-7354-Ver1.0.0 - Path Traversal
CVSS 7.5
CVE-2023-6825 CRITICAL
Mndpsingh287 File Manager < 7.2.1 - Path Traversal
CVSS 9.9
CVE-2023-42791 HIGH
Fortinet Fortimanager < 6.2.12 - Path Traversal
CVSS 8.8
CVE-2023-49801 MEDIUM
Lifplatforms Lif Auth Server < 1.4.0 - Path Traversal
CVSS 4.2
CVE-2023-31036 HIGH
NVIDIA Triton Inference Server - Path Traversal
CVSS 7.5
CVE-2023-50255 CRITICAL
Deepin-compressor < 5.12.21 - Path Traversal
CVSS 9.3
CVE-2023-6722 HIGH
Europeana Repox - Path Traversal
CVSS 7.5
CVE-2023-6307 MEDIUM
jeecgboot JimuReport <1.6.1 - Path Traversal
CVSS 6.3
CVE-2023-5189 MEDIUM
Ansible - Path Traversal
CVSS 6.3
CVE-2023-42783 HIGH
Fortinet Fortiwlm < 8.5.4 - Path Traversal
CVSS 7.5
CVE-2023-47613 MEDIUM
Telit Bgs5 Firmware - Path Traversal
CVSS 4.4
CVE-2023-46119 HIGH
Parse Server <5.5.6,6.3.1 - Info Disclosure
CVSS 7.5
CVE-2023-37913 CRITICAL
Xwiki < 14.10.8 - Path Traversal
CVSS 9.9
CVE-2023-3701 CRITICAL
Aquaesolutions Aqua Drive - Path Traversal
CVSS 9.9
CVE-2023-3512 HIGH
Setelsa Security's ConacWin CB <3.8.2.2 - Path Traversal
CVSS 7.5
CVE-2023-42456 LOW
Memorysafety Sudo < 0.2.1 - Path Traversal
CVSS 3.1
Details
Vulnerabilities 391