CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

391 vulnerabilities with CWE-23
CVE-2025-26645 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20947 - Improper Access Control
CVSS 8.8
CVE-2025-27610 HIGH
Rack < 2.2.13 - Path Traversal
CVSS 7.5
CVE-2025-23410 CRITICAL
GMOD Apollo - Path Traversal
CVSS 9.8
CVE-2025-25130 HIGH
Delete Comments By Status <2.1.1 - Path Traversal
CVSS 7.5
CVE-2025-27410 MEDIUM
PwnDoc <1.2.0 - Path Traversal
CVSS 6.5
CVE-2025-1599 MEDIUM
Mayurik Best Church Management Software - Path Traversal
CVSS 5.4
CVE-2025-1588 MEDIUM
Phpgurukul Online Nurse Hiring System - Path Traversal
CVSS 6.5
CVE-2025-1584 MEDIUM
Org.noear Solon-web-staticfiles < 3.0.9 - Path Traversal
CVSS 4.3
CVE-2025-20059 CRITICAL
PingAM Java Policy Agent <5.10.3-2024.9 - Path Traversal
CVSS 9.1
CVE-2025-0822 MEDIUM
Bitapps Bit Assist < 1.5.3 - Path Traversal
CVSS 6.5
CVE-2025-26349 HIGH
Q-free Maxtime < 2.11.0 - Path Traversal
CVSS 7.2
CVE-2025-1086 MEDIUM
Safetytest Cloud-Master Server <1.1.1 - Path Traversal
CVSS 5.3
CVE-2025-23011 HIGH
Fedorarepository Fcrepo < 6.5.1 - Path Traversal
CVSS 8.8
CVE-2025-0390 MEDIUM
Huayi-tec Jeewms < 2025-01-01 - Path Traversal
CVSS 5.3
CVE-2025-0225 MEDIUM
Tsinghua Unigroup Electronic Archives System 3.2.210802(62532 - Pat...
CVSS 4.3
CVE-2024-47856 CRITICAL
RSA Authentication Agent <7.4.7 - Path Traversal
CVSS 9.8
CVE-2024-48892 MEDIUM
Fortinet Fortisoar < 7.5.2 - Path Traversal
CVSS 6.8
CVE-2024-40588 MEDIUM
Fortinet FortiCamera <all> - Path Traversal
CVSS 4.4
CVE-2024-9363 HIGH
Polyaxon - DoS
CVSS 7.5
CVE-2024-8551 CRITICAL
modelscope/agentscope < - Path Traversal
CVSS 9.1
CVE-2024-7058 MEDIUM
Lollms Web UI - Path Traversal
CVSS 4.4
CVE-2024-6583 MEDIUM
stangirard/quivr - Path Traversal
CVSS 4.3
CVE-2024-6483 MEDIUM
aimhubio/aim <3.19.3 - Path Traversal
CVSS 5.3
CVE-2024-10513 HIGH
Mintplexlabs Anythingllm < 1.2.2 - Path Traversal
CVSS 7.2
CVE-2024-8510 MEDIUM
N-central <2024.6 - Path Traversal
CVSS 5.3
Details
Vulnerabilities 391