CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
461 vulnerabilities with CWE-23
CVE-2025-25048
MEDIUM
IBM Jazz Foundation <7.0.2-7.1.0 - Privilege Escalation
CVSS 6.5
CVE-2025-55748
HIGH
XWiki Platform <16.10.6 - Info Disclosure
CVSS 7.5
CVE-2025-55747
CRITICAL
XWiki Platform <16.10.6 - Info Disclosure
CVSS 9.1
CVE-2025-9570
MEDIUM
Sunnet eHRD CTMS - Authenticated Arbitrary File Read via Relative Path Traversal
CVSS 4.9
CVE-2025-55202
MEDIUM
Opencast < 17.7 - Relative Path Traversal in UI Config Module
CVSS 5.3
CVE-2025-9639
HIGH
Ai3 QbiCRMGateway 7.5.1-8.5.02 - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-8464
MEDIUM
Contact Form 7 <1.3.9.0 - Path Traversal
CVSS 5.3
CVE-2025-53779
HIGH
Windows Kerberos - Privilege Escalation
CVSS 7.2
CVE-2025-55013
MEDIUM
Assemblyline 4 <4.6.1.dev138 - Path Traversal
CVSS 4.2
CVE-2025-51052
MEDIUM
Vedo Suite <2024.17 - Path Traversal
CVSS 6.5
CVE-2025-53082
MEDIUM
Samsung Data Management Server Firmware 2.0.0-2.3.13.1 - Arbitrary File Deletion via Relative Path Traversal
CVSS 6.1
CVE-2025-54531
HIGH
JetBrains TeamCity < 2025.07 - Path Traversal via Plugin Unpacking on Windows
CVSS 7.7
CVE-2025-54317
HIGH
Logpoint < 7.6.0 - Authenticated Remote Code Execution via Layout Template Path Traversal
CVSS 8.4
CVE-2025-46002
MEDIUM
simogeo filemanager <= 2.5.0 - Directory Traversal via filemanager.php Endpoint
CVSS 6.5
CVE-2025-7619
HIGH
BatchSignCS < 3.318 - Arbitrary File Write via Malicious Website
CVSS 8.8
CVE-2025-48817
HIGH
Remote Desktop Client - Path Traversal
CVSS 8.8
CVE-2025-7146
HIGH
iPublish System - Unauthenticated Arbitrary File Read via Relative Path Traversal
CVSS 7.5
CVE-2025-52207
CRITICAL
MikoPBX <2024.1.114 - Code Injection
CVSS 9.9
CVE-2025-44163
MEDIUM
raspap-webgui < 3.3.6 - Authenticated Directory Traversal and Arbitrary File Write via Entity Parameter
CVSS 6.3
CVE-2025-52922
HIGH
InnoShop <= 0.4.1 - Authenticated Directory Traversal via FileManager API
CVSS 7.4
CVE-2025-34510
HIGH
Sitecore XP CVE-2025-34510 Post-Authentication Remote Code Execution
CVSS 8.8
CVE-2025-33112
HIGH
IBM AIX 7.3 & VIOS 4.1.1 - Code Injection
CVSS 8.4
CVE-2025-3365
CRITICAL
B. Braun Melsungen AG OnlineSuite 3.0 - Path Traversal
CVSS 9.8
CVE-2025-49466
MEDIUM
aerc < 93bec0de8ed5ab3d6b1f01026fe2ef20fa154329 - Path Traversal in Attachment Handling
CVSS 5.8
CVE-2025-48957
HIGH
AstrBot 3.4.4-3.5.12 - Path Traversal and Information Disclosure via Dashboard Feature
CVSS 7.5
Details
Vulnerabilities
461