CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

417 vulnerabilities with CWE-23
CVE-2024-5547 HIGH
stitionai devika - Directory Traversal via /api/download-project-pdf project_name Parameter
CVSS 7.5
CVE-2024-37138 MEDIUM
Dell PowerProtect DD < 8.0, LTS < 7.13.1.0, LTS < 7.10.1.30, LTS < 7.7.5.40 - Relative Path Traversal
CVSS 4.1
CVE-2024-3497 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Path Traversal and Arbitrary File Write
CVSS 8.8
CVE-2024-2461 MEDIUM
Hitachi Energy FOX61x and XMC20 - Path Traversal
CVE-2024-4330 LOW
lollms_web_ui 9.6 - Path Traversal via 'category' Parameter in 'list_personalities' Endpoint
CVSS 3.3
CVE-2024-36362 MEDIUM
JetBrains TeamCity <2022.04.7-2024.03.2 - Path Traversal
CVSS 6.5
CVE-2024-35186 HIGH
Crates.io Gix-worktree-state < 0.11.0 - Path Traversal
CVSS 8.8
CVE-2024-33615 HIGH
CyberPower PowerPanel - Path Traversal
CVSS 8.8
CVE-2024-30010 HIGH
Microsoft Windows Hyper-V - Remote Code Execution
CVSS 8.8
CVE-2024-34712 MEDIUM
Oceanic.js < 1.10.4 - Path Traversal via Unencoded API Endpoint Input
CVSS 6.5
CVE-2024-0549 HIGH
mintplex-labs/anything-llm - Path Traversal
CVSS 8.1
CVE-2024-32005 HIGH
NiceGUI <1.4.21 - Local File Inclusion
CVSS 8.2
CVE-2024-3025 CRITICAL
AnythingLLM < 1.0.0 - Path Traversal via Logo Filename Manipulation
CVSS 9.9
CVE-2024-0335 HIGH
ABB Symphony Plus S+ Operations Relative Path Traversal in VPNI Feature
CVSS 7.5
CVE-2024-20352 MEDIUM
Cisco Emergency Responder - Path Traversal
CVSS 4.9
CVE-2024-20310 MEDIUM
Cisco Unified Communications Manager IM & Presence Service Stored XSS via Web Interface
CVSS 6.1
CVE-2024-25944 MEDIUM
Dell OpenManage Enterprise < 4.0.1 - Unauthenticated Path Traversal
CVSS 5.7
CVE-2024-2053 HIGH
Artica Proxy - Unauthenticated Arbitrary File Read via Local File Inclusion Bypass
CVSS 7.5
CVE-2024-24578 CRITICAL
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVSS 10.0
CVE-2024-27770 HIGH
Unitronics Unistream Unilogic <1.35.227 - Path Traversal
CVSS 8.8
CVE-2024-22398 MEDIUM
SonicWall Email Security Appliance - Path Traversal
CVSS 4.9
CVE-2024-2318 MEDIUM
ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028 - Path Traversal via Service Port 9999 File Download
CVSS 4.3
CVE-2024-27199 HIGH KEV
TeamCity < 2023.11.4 - Authentication Bypass
CVSS 7.3
CVE-2024-0550 MEDIUM
AnythingLLM < 1.0.0 - Authenticated Relative Path Traversal via Profile Picture API
CVSS 6.5
CVE-2024-22226 LOW
Dell Unity Operating Environment < 5.4.0.0.5.094 - Authenticated Path Traversal via svc_supportassist Utility
CVSS 3.3
Details
Vulnerabilities 417