CWE-23
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
462 vulnerabilities with CWE-23
CVE-2025-27410
MEDIUM
pwndoc < 1.2.0 - Authenticated Path Traversal and Remote Code Execution via Backup Restore
CVSS 6.5
CVE-2025-1599
MEDIUM
Best Church Management Software 1.0 - Path Traversal via old_cat_img Parameter
CVSS 5.4
CVE-2025-1588
MEDIUM
PHPGurukul Online Nurse Hiring System 1.0 - Path Traversal via Profile Picture Upload
CVSS 6.5
CVE-2025-1584
MEDIUM
Solon < 3.0.9 - Path Traversal via StaticMappings
CVSS 4.3
CVE-2025-20059
CRITICAL
PingAM Java Policy Agent <5.10.3-2024.9 - Path Traversal
CVSS 9.1
CVE-2025-0822
MEDIUM
Bit Assist < 1.5.3 - Authenticated Path Traversal via fileID Parameter
CVSS 6.5
CVE-2025-26349
HIGH
Q-Free MaxTime <= 2.11.0 - Authenticated Arbitrary File Write via File Upload Path Traversal
CVSS 7.2
CVE-2025-1086
MEDIUM
Safetytest Cloud-Master Server <1.1.1 - Path Traversal
CVSS 5.3
CVE-2025-23011
HIGH
Fedorarepository Fcrepo < 6.5.1 - Path Traversal
CVSS 8.8
CVE-2025-0390
MEDIUM
Guangzhou Huayi Intelligent Technology Jeewms < 2025-01-01 - Path Traversal via /wmOmNoticeHController.do
CVSS 5.3
CVE-2025-0225
MEDIUM
Tsinghua Unigroup Electronic Archives System 3.2.210802(62532 - Pat...
CVSS 4.3
CVE-2024-47856
CRITICAL
RSA Authentication Agent <7.4.7 - Path Traversal
CVSS 9.8
CVE-2024-48892
MEDIUM
FortiSOAR 7.3.0-7.5.1, 7.6.0 - Authenticated Arbitrary File Read via Malicious Solution Pack Upload
CVSS 6.8
CVE-2024-40588
MEDIUM
Fortinet FortiCamera <all> - Path Traversal
CVSS 4.4
CVE-2024-9363
HIGH
Polyaxon - Unauthenticated Arbitrary File Deletion and Denial of Service via Container File Removal
CVSS 7.5
CVE-2024-8551
CRITICAL
modelscope/agentscope < - Path Traversal
CVSS 9.1
CVE-2024-7058
MEDIUM
lollms_web_ui - Path Traversal via Relative Path Bypass in sanitize_path Function
CVSS 4.4
CVE-2024-6583
MEDIUM
quivr - Path Traversal and Arbitrary File Write via S3 Upload Request
CVSS 4.3
CVE-2024-6483
MEDIUM
aimhubio/aim <3.19.3 - Path Traversal
CVSS 5.3
CVE-2024-10513
HIGH
AnythingLLM < 1.2.2 - Authenticated Path Traversal and Arbitrary File Manipulation via Document Uploads Manager
CVSS 7.2
CVE-2024-8510
MEDIUM
n-able n-central < 2024.6 - Path Traversal to Apache Tomcat WEB-INF Directory
CVSS 5.3
CVE-2024-54449
HIGH
LogicalDOC < 9.1 - Authenticated Arbitrary File Write and Remote Code Execution via Document API
CVSS 8.8
CVE-2024-12019
HIGH
LogicalDOC Community < 9.1 - Authenticated Relative Path Traversal
CVE-2024-56340
MEDIUM
IBM Cognos Analytics 11.2.0-11.2.4 FP5 - Local File Inclusion via Deficon Parameter
CVSS 6.5
CVE-2024-47051
CRITICAL
Mautic < 5.2.3 - Authenticated Remote Code Execution and Path Traversal via Asset Upload
CVSS 9.1
Details
Vulnerabilities
462