CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
417 vulnerabilities with CWE-23
CVE-2025-66386
MEDIUM
MISP < 2.5.27 - Authenticated Path Traversal in EventReport Picture View
CVSS 4.1
CVE-2025-40605
MEDIUM
SonicWall Email Security Appliance Firmware < 10.0.33.8195 - Path Traversal via Directory Traversal Sequences
CVSS 5.3
CVE-2025-64757
LOW
Astro < 5.14.3 - Unauthenticated Arbitrary Local File Read via Image Optimization Endpoint
CVSS 3.5
CVE-2025-13199
MEDIUM
Email Logging Interface 2.0 - Path Traversal via Username Argument
CVSS 5.3
CVE-2025-64446
CRITICAL
KEV
Fortinet FortiWeb unauthenticated RCE
CVSS 9.8
CVE-2025-13161
HIGH
IQ-Support - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-64714
MEDIUM
PrivateBin 1.7.7-2.0.3 - Unauthenticated Local File Inclusion via Template Cookie
CVSS 5.8
CVE-2025-58464
HIGH
QuMagie >= 2.7.0 < 2.7.3 - Relative Path Traversal
CVSS 7.5
CVE-2025-58463
MEDIUM
Download Station <5.10.0.304-5.10.0.305 - Path Traversal
CVSS 4.9
CVE-2025-46363
MEDIUM
Dell Secure Connect Gateway <5.30.00.00 - Path Traversal
CVSS 4.3
CVE-2025-55752
HIGH
Apache Tomcat 8.5.6-8.5.100, 9.0.0.M11-9.0.108, 10.1.0-M1-10.1.44, 11.0.0-M1-11.0.10 - RCE via URI Rewrite Bypass
CVSS 7.5
CVE-2025-60023
MEDIUM
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 4.0
CVE-2025-59776
MEDIUM
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 4.0
CVE-2025-58429
HIGH
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 7.5
CVE-2025-62498
HIGH
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 8.8
CVE-2025-58456
MEDIUM
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 6.8
CVE-2025-58078
HIGH
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 7.5
CVE-2025-11898
HIGH
Agentflow - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-10249
MEDIUM
Slider Revolution <6.7.37 - Privilege Escalation
CVSS 6.5
CVE-2025-62187
LOW
Anki < 25.02.6 - Path Traversal and Arbitrary File Write via Crafted Sound File References
CVSS 2.9
CVE-2025-59835
HIGH
LangBot <4.3.5 - Privilege Escalation
CVE-2025-59682
LOW
Django 4.2-4.2.24, 5.1-5.1.12, 5.2-5.2.6 - Relative Path Traversal via Archive Extraction
CVSS 3.1
CVE-2025-60020
MEDIUM
NNCP < 8.12.0 - Path Traversal via Crafted Packet Data
CVSS 6.4
CVE-2025-59341
HIGH
esm.sh <= 136 - Local File Inclusion via URL Handling
CVE-2025-59456
MEDIUM
JetBrains TeamCity < 2025.07.2 - Path Traversal via Project Archive Upload
CVSS 5.5
Details
Vulnerabilities
417