CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
417 vulnerabilities with CWE-23
CVE-2023-42456
LOW
sudo-rs < 0.2.1 - Path Traversal via Username with Special Characters
CVSS 3.3
CVE-2023-4760
HIGH
Eclipse RAP 3.0.0-3.25.0 - Remote Code Execution via FileUpload Path Traversal
CVSS 7.6
CVE-2023-4914
HIGH
cecil < 7.47.1 - Path Traversal
CVSS 7.5
CVE-2023-4897
CRITICAL
mintplex-labs/anything-llm <0.0.1 - Path Traversal
CVSS 9.8
CVE-2023-38185
HIGH
Microsoft Exchange Server - Remote Code Execution
CVSS 8.8
CVE-2023-35359
HIGH
Windows Kernel - Elevation of Privilege via Relative Path Traversal
CVSS 7.8
CVE-2023-34394
HIGH
Keysight Geolocation Server < 2.4.2 - Unauthenticated Arbitrary File Upload and Deletion via Improper Path Validation
CVSS 7.8
CVE-2023-2913
HIGH
Rockwell Automation ThinManager 13.0.0-13.0.1 - Path Traversal via API Feature
CVSS 7.5
CVE-2023-34117
LOW
Zoom Client SDK <5.15.0 - Info Disclosure
CVSS 3.3
CVE-2023-37288
MEDIUM
SmartBPM.NET - Unauthenticated Path Traversal via File Download Function
CVSS 6.5
CVE-2023-33144
MEDIUM
Visual Studio Code < 1.79 - Spoofing via Relative Path Traversal
CVSS 6.6
CVE-2023-27993
MEDIUM
FortiADC 7.2.0 and before 7.1.1 - Authenticated Path Traversal via CLI Commands
CVSS 6.0
CVE-2023-2356
HIGH
mlflow/mlflow <2.3.1 - Path Traversal
CVSS 7.5
CVE-2023-30630
HIGH
dmidecode < 3.5 - Arbitrary File Write via -dump-bin Option
CVSS 7.1
CVE-2023-29189
MEDIUM
SAP CRM (WebClient UI) - Auth Bypass
CVSS 5.4
CVE-2023-20066
MEDIUM
Cisco IOS XE - Authenticated Path Traversal in Web UI
CVSS 6.5
CVE-2023-23391
MEDIUM
Office for Android - Spoofing via Relative Path Traversal
CVSS 5.5
CVE-2023-1112
MEDIUM
Drag and Drop Multiple File Upload Contact Form 7 < 5.0.6.3 - Path Traversal via upload_name Parameter
CVSS 4.7
CVE-2023-0511
CRITICAL
ForgeRock Java Policy Agent < 5.10.1 - Authentication Bypass via Relative Path Traversal
CVSS 9.1
CVE-2023-0339
CRITICAL
ForgeRock Access Management Web Policy Agent < 5.10.1 - Authentication Bypass via Relative Path Traversal
CVSS 9.1
CVE-2023-1045
LOW
MuYuCMS 2.2 - Path Traversal via /admin.php/accessory/filesdel.html filedelur Parameter
CVSS 3.8
CVE-2023-1044
MEDIUM
MuYuCMS 2.2 - Path Traversal via /editor/index.php file_path Parameter
CVSS 4.3
CVE-2023-1043
MEDIUM
MuYuCMS 2.2 - Path Traversal via dir_path Parameter in Editor
CVSS 4.3
CVE-2023-23784
MEDIUM
FortiWeb 6.3.6-6.3.20 and 7.0.0-7.0.2 - Path Traversal via Crafted Web Requests
CVSS 5.7
CVE-2023-23778
MEDIUM
FortiWeb 6.2.3-6.2.6, 6.3, 6.4, 7.0-7.0.1 - Authenticated Path Traversal via Crafted Web Requests
CVSS 4.9
Details
Vulnerabilities
417