CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
461 vulnerabilities with CWE-23
CVE-2025-64714
MEDIUM
PrivateBin 1.7.7-2.0.3 - Unauthenticated Local File Inclusion via Template Cookie
CVSS 5.8
CVE-2025-58464
HIGH
QuMagie >= 2.7.0 < 2.7.3 - Relative Path Traversal
CVSS 7.5
CVE-2025-58463
MEDIUM
Download Station <5.10.0.304-5.10.0.305 - Path Traversal
CVSS 4.9
CVE-2025-46363
MEDIUM
Dell Secure Connect Gateway <5.30.00.00 - Path Traversal
CVSS 4.3
CVE-2025-55752
HIGH
Apache Tomcat 8.5.6-8.5.100, 9.0.0.M11-9.0.108, 10.1.0-M1-10.1.44, 11.0.0-M1-11.0.10 - RCE via URI Rewrite Bypass
CVSS 7.5
CVE-2025-60023
MEDIUM
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 4.0
CVE-2025-59776
MEDIUM
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 4.0
CVE-2025-58429
HIGH
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 7.5
CVE-2025-62498
HIGH
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 8.8
CVE-2025-58456
MEDIUM
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 6.8
CVE-2025-58078
HIGH
Productivity Suite <4.4.1.19 - Path Traversal
CVSS 7.5
CVE-2025-11898
HIGH
Agentflow - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-10249
MEDIUM
Slider Revolution <6.7.37 - Privilege Escalation
CVSS 6.5
CVE-2025-62187
LOW
Anki < 25.02.6 - Path Traversal and Arbitrary File Write via Crafted Sound File References
CVSS 2.9
CVE-2025-59835
HIGH
LangBot <4.3.5 - Privilege Escalation
CVE-2025-59682
LOW
Django 4.2-4.2.24, 5.1-5.1.12, 5.2-5.2.6 - Relative Path Traversal via Archive Extraction
CVSS 3.1
CVE-2025-60020
MEDIUM
NNCP < 8.12.0 - Path Traversal via Crafted Packet Data
CVSS 6.4
CVE-2025-59341
HIGH
esm.sh <= 136 - Local File Inclusion via URL Handling
CVE-2025-59456
MEDIUM
JetBrains TeamCity < 2025.07.2 - Path Traversal via Project Archive Upload
CVSS 5.5
CVE-2025-59336
MEDIUM
Luanox < 0.1.1 - Path Traversal and Denial of Service via Malicious Package Name
CVE-2025-55115
HIGH
Control-M/Agent <9.0.20 - Privilege Escalation
CVSS 8.8
CVE-2025-10203
HIGH
Digilent WaveForms < 3.24.3 - Arbitrary Code Execution via Crafted .DWF3WORK File
CVSS 7.8
CVE-2025-58760
HIGH
Tautulli < 2.16.0 - Unauthenticated Path Traversal via Image API Endpoint
CVSS 8.6
CVE-2025-53609
MEDIUM
FortiWeb <7.6.4-7.2.11-7.0.11 - Path Traversal
CVSS 4.9
CVE-2025-58752
MEDIUM
Vite <7.1.5, 7.0.7, 6.3.6, 5.4.20 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
461