CWE-23

Relative Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

391 vulnerabilities with CWE-23
CVE-2024-37138 MEDIUM
Dell Data Domain Operating System < 7.7.5.40 - Path Traversal
CVSS 4.1
CVE-2024-3497 HIGH
Toshiba Printer - Path Traversal
CVSS 8.8
CVE-2024-2461 MEDIUM
Unknown Product <Unknown Version - Path Traversal
CVE-2024-4330 LOW
Lollms Web UI < 9.8 - Path Traversal
CVSS 3.3
CVE-2024-36362 MEDIUM
JetBrains TeamCity <2022.04.7-2024.03.2 - Path Traversal
CVSS 6.5
CVE-2024-35186 HIGH
Crates.io Gix-worktree-state < 0.11.0 - Path Traversal
CVSS 8.8
CVE-2024-33615 HIGH
CyberPower PowerPanel - Path Traversal
CVSS 8.8
CVE-2024-30010 HIGH
Windows Hyper-V < - RCE
CVSS 8.8
CVE-2024-34712 MEDIUM
NPM Oceanic.js < 1.10.4 - Path Traversal
CVSS 6.5
CVE-2024-0549 HIGH
mintplex-labs/anything-llm - Path Traversal
CVSS 8.1
CVE-2024-32005 HIGH
NiceGUI <1.4.21 - Local File Inclusion
CVSS 8.2
CVE-2024-3025 CRITICAL
Mintplexlabs Anythingllm < 1.0.0 - Path Traversal
CVSS 9.9
CVE-2024-0335 HIGH
ABB VPNI - Unknown Vuln
CVSS 7.5
CVE-2024-20352 MEDIUM
Cisco Emergency Responder - Path Traversal
CVSS 4.9
CVE-2024-20310 MEDIUM
Cisco Unified CM IM&P - XSS
CVSS 6.1
CVE-2024-25944 MEDIUM
Dell Openmanage Enterprise < 4.0.1 - Path Traversal
CVSS 5.7
CVE-2024-2053 HIGH
Articatech Artica Proxy - Path Traversal
CVSS 7.5
CVE-2024-24578 CRITICAL
RaspberryMatic unauthenticated Remote Code Execution vulnerability through HMServer File Upload.
CVSS 10.0
CVE-2024-27770 HIGH
Unitronics Unistream Unilogic <1.35.227 - Path Traversal
CVSS 8.8
CVE-2024-22398 MEDIUM
SonicWall Email Security Appliance - Path Traversal
CVSS 4.9
CVE-2024-2318 MEDIUM
Zkteco Zkbio Media - Path Traversal
CVSS 4.3
CVE-2024-27199 HIGH KEV
TeamCity < 2023.11.4 - Authentication Bypass
CVSS 7.3
CVE-2024-0550 MEDIUM
Privileged User - Info Disclosure
CVSS 6.5
CVE-2024-22226 LOW
Dell Unity <5.4 - Path Traversal
CVSS 3.3
CVE-2024-24942 MEDIUM
JetBrains TeamCity <2023.11.3 - Path Traversal
CVSS 5.3
Details
Vulnerabilities 391