CWE-24

Path Traversal: '../filedir'

Parent: CWE-23 - Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

108 vulnerabilities with CWE-24
CVE-2024-8409 MEDIUM
ABCD ABCD2 <2.2.0-beta-1 - Path Traversal
CVSS 4.3
CVE-2024-37403 MEDIUM
Ivanti Docs@work < 2.26.0 - Path Traversal
CVSS 5.5
CVE-2024-23657 HIGH
Nuxt < 1.3.9 - Path Traversal
CVSS 8.8
CVE-2024-6746 MEDIUM
NaiboWang EasySpider 0.6.2 - Path Traversal
CVSS 4.3
CVE-2024-4790 MEDIUM
Dedecms - Path Traversal
CVSS 4.3
CVE-2024-3686 MEDIUM
Dedecms - Path Traversal
CVSS 4.3
CVE-2024-3227 MEDIUM
Weaver E-office < 9.5 - Path Traversal
CVSS 4.7
CVE-2024-3218 MEDIUM
Shibang Communications IP Network Intercom Broadcasting System 1.0 ...
CVSS 5.4
CVE-2024-2825 MEDIUM
Lakernote Easyadmin < 2024-03-15 - Path Traversal
CVSS 6.3
CVE-2024-22079 HIGH
Elspec G5 <1.1.4.15 - Path Traversal
CVSS 7.5
CVE-2024-2564 MEDIUM
Pandax < 2024-03-10 - Path Traversal
CVSS 6.3
CVE-2024-2563 MEDIUM
Pandax < 2024-03-10 - Path Traversal
CVSS 5.4
CVE-2024-2318 MEDIUM
Zkteco Zkbio Media - Path Traversal
CVSS 4.3
CVE-2024-1459 MEDIUM
Redhat Undertow < 2.2.31.Final - Path Traversal
CVSS 5.3
CVE-2024-0989 MEDIUM
Sichuan Yougou Technology KuERP <1.0.4 - Path Traversal
CVSS 5.4
CVE-2024-0882 MEDIUM
qwdigital LinkWechat 5.1.0 - Path Traversal
CVSS 4.3
CVE-2024-0465 LOW
code-projects Employee Profile Management System 1.0 - Path Traversal
CVSS 3.5
CVE-2024-0417 MEDIUM
Csdeshang Dsshop < 2.1.5 - Path Traversal
CVSS 5.4
CVE-2024-0416 MEDIUM
Csdeshang Dsmall < 5.0.3 - Path Traversal
CVSS 5.4
CVE-2024-0354 MEDIUM
Unknown-o Download-station < 1.1.8 - Path Traversal
CVSS 5.3
CVE-2024-0341 LOW
Inis < 2.0.1 - Path Traversal
CVSS 3.5
CVE-2023-53691 HIGH
Hikvision CSMP iSecure Center <2023-06-25 - Path Traversal
CVSS 8.3
CVE-2023-52076 HIGH
Atril Document Viewer <1.26.2 - Path Traversal
CVSS 8.5
CVE-2023-6699 CRITICAL
Wpcompress WP Compress < 6.10.33 - Path Traversal
CVSS 9.1
CVE-2023-7134 MEDIUM
Oretnom23 Medicine Tracker System - Path Traversal
CVSS 6.3
Details
Vulnerabilities 108