CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
461 vulnerabilities with CWE-23
CVE-2025-53829
HIGH
ownCloud 10 is vulnerable to Relative Path Traversal
CVSS 8.0
CVE-2025-41280
HIGH
Waterfall WF-500 < 7.9.1.0 R2502171040 - Relative Path Traversal
CVSS 7.8
CVE-2025-41271
HIGH
Waterfall WF-500 < 7.9.1.0 R2502171040 - Relative Path Traversal
CVSS 7.5
CVE-2025-41268
CRITICAL
Waterfall WF-500 < 7.9.1.0 R2502171040 - Relative Path Traversal
CVSS 9.1
CVE-2025-48977
MEDIUM
Apache Ignite: REST HTTP arbitrary file read vulnerability
CVSS 6.5
CVE-2025-24819
MEDIUM
A Relative Path Traversal vulnerability in Nokia MantaRay NM
CVSS 5.7
CVE-2025-62878
CRITICAL
Rancher local-path-provisioner < 0.0.34 - Path Traversal via pathPattern Parameter
CVSS 9.9
CVE-2025-58467
MEDIUM
Qsync Central <5.0.0.4 - Path Traversal
CVSS 6.5
CVE-2025-22873
LOW
GO < 1.23.9 - Path Traversal
CVSS 3.8
CVE-2025-68472
HIGH
MindsDB < 25.11.1 - Unauthenticated Path Traversal and Arbitrary File Read via File Upload API
CVSS 8.1
CVE-2025-67366
HIGH
sylphx filesystem-mcp 0.5.8 - Path Traversal via Symlink Handling Bypass
CVSS 7.5
CVE-2025-15225
HIGH
Sun.net WMPro 5.0-5.1 - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-66737
MEDIUM
Yealink T21P_E2 Phone <52.84.0.15 - Path Traversal
CVSS 4.3
CVE-2025-57403
HIGH
Cola Dnslog 1.3.2 - Directory Traversal via DNS TXT Record Processing
CVSS 7.5
CVE-2025-15015
HIGH
Enterprise Cloud Database - Path Traversal
CVSS 7.5
CVE-2025-66626
HIGH
Argo Workflows <3.7.4 - Code Injection
CVSS 8.1
CVE-2025-62552
HIGH
Microsoft Access 2016 < 16.0.5530.1000 - Unauthenticated Relative Path Traversal
CVSS 7.8
CVE-2025-12097
HIGH
NI System Web Server <2012 - Info Disclosure
CVSS 7.5
CVE-2025-13771
MEDIUM
WebITR < 2.1.0.34 - Authenticated Arbitrary File Read via Relative Path Traversal
CVSS 6.5
CVE-2025-66386
MEDIUM
MISP < 2.5.27 - Authenticated Path Traversal in EventReport Picture View
CVSS 4.1
CVE-2025-40605
MEDIUM
SonicWall Email Security Appliance Firmware < 10.0.33.8195 - Path Traversal via Directory Traversal Sequences
CVSS 5.3
CVE-2025-64757
LOW
Astro < 5.14.3 - Unauthenticated Arbitrary Local File Read via Image Optimization Endpoint
CVSS 3.5
CVE-2025-13199
MEDIUM
Email Logging Interface 2.0 - Path Traversal via Username Argument
CVSS 5.3
CVE-2025-64446
CRITICAL
KEV
Fortinet FortiWeb unauthenticated RCE
CVSS 9.8
CVE-2025-13161
HIGH
IQ-Support - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
Details
Vulnerabilities
461