CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

391 vulnerabilities with CWE-23
CVE-2024-54449 HIGH
Logicaldoc < 9.1 - Path Traversal
CVSS 8.8
CVE-2024-12019 HIGH
API - Info Disclosure
CVE-2024-56340 MEDIUM
IBM Cognos Analytics < 11.2.4 - Path Traversal
CVSS 6.5
CVE-2024-47051 CRITICAL
Mautic <5.2.3 - RCE
CVSS 9.1
CVE-2024-13791 MEDIUM
Bitapps Bit Assist < 1.5.3 - Path Traversal
CVSS 4.9
CVE-2024-54462 HIGH
Flutter Image Picker Android < 0.8.12\+18 - Path Traversal
CVSS 7.1
CVE-2024-54461 HIGH
Flutter File Selector Android < 0.5.1\+12 - Path Traversal
CVSS 7.1
CVE-2024-52012 MEDIUM
Apache Solr <9.7.0 - Path Traversal
CVSS 5.4
CVE-2024-46664 MEDIUM
Fortinet Fortirecorder < 7.0.5 - Path Traversal
CVSS 5.5
CVE-2024-32115 MEDIUM
Fortinet FortiManager <7.4.3 - Path Traversal
CVSS 5.5
CVE-2024-13130 MEDIUM
Dahua IPC-HFW1200S-20241222 - Path Traversal
CVSS 4.3
CVE-2024-12897 MEDIUM
Intelbras VIP S3020 G2-VIP S4320 G2 20241222 - Path Traversal
CVSS 4.3
CVE-2024-12645 MEDIUM
topm-client - Path Traversal
CVSS 6.5
CVE-2024-12642 HIGH
CHT Tenderdoctransfer < 0.41.157 - CSRF
CVSS 8.1
CVE-2024-49062 MEDIUM
Microsoft Sharepoint Server - Path Traversal
CVSS 6.5
CVE-2024-12482 MEDIUM
Cjbi Wetech-cms - Path Traversal
CVSS 4.3
CVE-2024-54154 HIGH
JetBrains YouTrack <2024.3.51866 - Path Traversal
CVSS 8.0
CVE-2024-11315 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11314 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11313 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11312 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11311 CRITICAL
TRCore - Path Traversal
CVSS 9.8
CVE-2024-11310 HIGH
TRCore - Path Traversal
CVSS 7.5
CVE-2024-11309 HIGH
TRCore - Path Traversal
CVSS 7.5
CVE-2024-35274 LOW
Fortinet Fortianalyzer < 7.4.3 - Path Traversal
CVSS 2.3
Details
Vulnerabilities 391