CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

391 vulnerabilities with CWE-23
CVE-2024-32116 MEDIUM
Fortinet Fortianalyzer < 7.2.6 - Path Traversal
CVSS 5.1
CVE-2024-11067 HIGH
Dlink Dsl6740c Firmware - Path Traversal
CVSS 7.5
CVE-2024-50453 HIGH
Webangon The Pack Elementor Addons < 2.1.0 - Path Traversal
CVSS 7.5
CVE-2024-10200 HIGH
Administrative Management System - Path Traversal
CVSS 7.5
CVE-2024-49253 HIGH
James Park Analyse Uploads <0.5 - Path Traversal
CVSS 8.6
CVE-2024-47637 HIGH
LiteSpeed Technologies LiteSpeed Cache <6.4.1 - Path Traversal
CVSS 8.8
CVE-2024-9983 HIGH
Enterprise Cloud Database - Info Disclosure
CVSS 7.5
CVE-2024-45731 HIGH
Splunk < 9.1.6 - Path Traversal
CVSS 8.0
CVE-2024-9923 MEDIUM
Teamplus Team+ Pro < 14.0.0 - Path Traversal
CVSS 4.9
CVE-2024-9922 HIGH
Teamplus Team+ Pro < 14.0.0 - Path Traversal
CVSS 7.5
CVE-2024-6985 MEDIUM
Lollms < 5.9.0 - Path Traversal
CVSS 4.4
CVE-2024-43614 MEDIUM
Microsoft Defender For Endpoint < 101.24052.0002 - Path Traversal
CVSS 5.5
CVE-2024-47949 MEDIUM
Jetbrains Teamcity < 2024.07.3 - Path Traversal
CVSS 4.9
CVE-2024-47948 MEDIUM
Jetbrains Teamcity < 2024.07.3 - Path Traversal
CVSS 4.9
CVE-2024-47769 HIGH
IDURAR - Path Traversal
CVSS 7.5
CVE-2024-20449 HIGH
Cisco Nexus Dashboard Fabric Controller - RCE
CVSS 8.8
CVE-2024-9405 MEDIUM
Pluck CMS <4.7.18 - Path Traversal
CVSS 5.3
CVE-2024-45816 MEDIUM
Linuxfoundation Backstage < 1.10.13 - Path Traversal
CVSS 6.5
CVE-2024-43454 HIGH
Microsoft Windows Server 2008 < 10.0.14393.7336 - Path Traversal
CVSS 7.1
CVE-2024-38258 MEDIUM
Windows Remote Desktop < - Info Disclosure
CVSS 6.5
CVE-2024-43399 HIGH
Opensecurity Mobile Security Framework < 4.0.7 - Path Traversal
CVSS 8.0
CVE-2024-7693 HIGH
Raidenmaild < 5.0.2 - Path Traversal
CVSS 7.5
CVE-2024-6433 HIGH
Application <version> - Info Disclosure
CVSS 7.5
CVE-2024-3122 MEDIUM
CHANGING Mobile - Info Disclosure
CVSS 4.9
CVE-2024-5547 HIGH
Stitionai Devika - Path Traversal
CVSS 7.5
Details
Vulnerabilities 391