CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

462 vulnerabilities with CWE-23
CVE-2024-49253 HIGH
James Park Analyse Uploads <0.5 - Path Traversal
CVSS 8.6
CVE-2024-47637 HIGH
LiteSpeed Technologies LiteSpeed Cache <6.4.1 - Path Traversal
CVSS 8.8
CVE-2024-9983 HIGH
Enterprise Cloud Database - Info Disclosure
CVSS 7.5
CVE-2024-45731 HIGH
Splunk Enterprise for Windows < 9.3.1, < 9.2.3, < 9.1.6 - Path Traversal and Arbitrary File Write
CVSS 8.0
CVE-2024-9923 MEDIUM
Team+ Pro 13.5.0-13.9.9 - Authenticated Arbitrary File Move via Page Parameter
CVSS 4.9
CVE-2024-9922 HIGH
Team+ Pro 13.5.0-13.9.9 - Unauthenticated Path Traversal via Page Parameter
CVSS 7.5
CVE-2024-6985 MEDIUM
lollms/lollms < 5.9.0 - Path Traversal via Personality Folder Parameter
CVSS 4.4
CVE-2024-43614 MEDIUM
Microsoft Defender for Endpoint < 101.24052.0002 - Authenticated Relative Path Traversal
CVSS 5.5
CVE-2024-47949 MEDIUM
JetBrains TeamCity < 2024.07.3 - Path Traversal and Arbitrary File Write via Backup File
CVSS 4.9
CVE-2024-47948 MEDIUM
JetBrains TeamCity < 2024.07.3 - Path Traversal via Server Backups
CVSS 4.9
CVE-2024-47769 HIGH
idurar < 4.1.0 - Unauthenticated Path Traversal via Public Endpoint
CVSS 7.5
CVE-2024-20449 HIGH
Cisco Nexus Dashboard Fabric Controller - RCE
CVSS 8.8
CVE-2024-9405 MEDIUM
Pluck CMS 4.7.18 - Unauthenticated Path Traversal
CVSS 5.3
CVE-2024-45816 MEDIUM
Backstage < 1.10.13 - Path Traversal in TechDocs Storage Provider
CVSS 6.5
CVE-2024-43454 HIGH
Microsoft Windows Server 2008 < 10.0.14393.7336 - Path Traversal
CVSS 7.1
CVE-2024-38258 MEDIUM
Windows Remote Desktop < - Info Disclosure
CVSS 6.5
CVE-2024-43399 HIGH
Mobile Security Framework < 4.0.7 - Path Traversal via Static Libraries Extraction
CVSS 8.0
CVE-2024-7693 HIGH
raidenmaild < 5.0.2 - Unauthenticated Path Traversal
CVSS 7.5
CVE-2024-6433 HIGH
Application <version> - Info Disclosure
CVSS 7.5
CVE-2024-3122 MEDIUM
CHANGING Mobile One Time Password < 3.11.2 - Authenticated Arbitrary File Read via File Download Functionality
CVSS 4.9
CVE-2024-5547 HIGH
stitionai devika - Directory Traversal via /api/download-project-pdf project_name Parameter
CVSS 7.5
CVE-2024-37138 MEDIUM
Dell PowerProtect DD < 8.0, LTS < 7.13.1.0, LTS < 7.10.1.30, LTS < 7.7.5.40 - Relative Path Traversal
CVSS 4.1
CVE-2024-3497 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Path Traversal and Arbitrary File Write
CVSS 8.8
CVE-2024-2461 MEDIUM
Hitachi Energy FOX61x and XMC20 - Path Traversal
CVE-2024-4330 LOW
lollms_web_ui 9.6 - Path Traversal via 'category' Parameter in 'list_personalities' Endpoint
CVSS 3.3
Details
Vulnerabilities 462