CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
417 vulnerabilities with CWE-23
CVE-2026-25057
CRITICAL
Markus < 2.9.1 - Path Traversal via Assignment Configuration Upload
CVSS 9.1
CVE-2026-25575
HIGH
NavigaTUM < 2026-02-03 - Unauthenticated Path Traversal and Arbitrary File Write via Propose Edits Endpoint
CVSS 7.5
CVE-2026-25121
HIGH
apko 0.14.8-1.1.0 - Path Traversal via dirFS Filesystem Abstraction
CVSS 7.5
CVE-2026-24909
MEDIUM
vltpkg/tar < 1.0.0-rc.10 - Path Traversal during Extraction
CVSS 5.9
CVE-2026-23890
MEDIUM
pnpm < 10.28.1 - Path Traversal via Bin Linking with Scope Normalization Bypass
CVSS 6.5
CVE-2026-23888
MEDIUM
pnpm < 10.28.1 - Path Traversal and Arbitrary File Write via Binary Fetcher
CVSS 6.5
CVE-2026-1022
HIGH
Gotac Statistics Database System < 1.0.3 - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-41280
HIGH
Waterfall WF-500 < 7.9.1.0 R2502171040 - Relative Path Traversal
CVSS 7.8
CVE-2025-41271
HIGH
Waterfall WF-500 < 7.9.1.0 R2502171040 - Relative Path Traversal
CVSS 7.5
CVE-2025-41268
CRITICAL
Waterfall WF-500 < 7.9.1.0 R2502171040 - Relative Path Traversal
CVSS 9.1
CVE-2025-48977
MEDIUM
Apache Ignite: REST HTTP arbitrary file read vulnerability
CVSS 6.5
CVE-2025-24819
MEDIUM
A Relative Path Traversal vulnerability in Nokia MantaRay NM
CVSS 5.7
CVE-2025-62878
CRITICAL
Rancher local-path-provisioner < 0.0.34 - Path Traversal via pathPattern Parameter
CVSS 9.9
CVE-2025-58467
MEDIUM
Qsync Central <5.0.0.4 - Path Traversal
CVSS 6.5
CVE-2025-22873
LOW
GO < 1.23.9 - Path Traversal
CVSS 3.8
CVE-2025-68472
HIGH
MindsDB < 25.11.1 - Unauthenticated Path Traversal and Arbitrary File Read via File Upload API
CVSS 8.1
CVE-2025-67366
HIGH
sylphx filesystem-mcp 0.5.8 - Path Traversal via Symlink Handling Bypass
CVSS 7.5
CVE-2025-15225
HIGH
Sun.net WMPro 5.0-5.1 - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-66737
MEDIUM
Yealink T21P_E2 Phone <52.84.0.15 - Path Traversal
CVSS 4.3
CVE-2025-57403
HIGH
Cola Dnslog 1.3.2 - Directory Traversal via DNS TXT Record Processing
CVSS 7.5
CVE-2025-15015
HIGH
Enterprise Cloud Database - Path Traversal
CVSS 7.5
CVE-2025-66626
HIGH
Argo Workflows <3.7.4 - Code Injection
CVSS 8.1
CVE-2025-62552
HIGH
Microsoft Access 2016 < 16.0.5530.1000 - Unauthenticated Relative Path Traversal
CVSS 7.8
CVE-2025-12097
HIGH
NI System Web Server <2012 - Info Disclosure
CVSS 7.5
CVE-2025-13771
MEDIUM
WebITR < 2.1.0.34 - Authenticated Arbitrary File Read via Relative Path Traversal
CVSS 6.5
Details
Vulnerabilities
417