CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

126 vulnerabilities with CWE-36
CVE-2025-5927 HIGH
Everest Forms and Everest Forms Pro <= 1.9.4 - Unauthenticated Arbitrary File Deletion via delete_entry_files()
CVSS 7.5
CVE-2025-4799 HIGH
WP-DownloadManager <= 1.68.10 - Authenticated Arbitrary File Deletion
CVSS 7.2
CVE-2025-36574 HIGH
Dell Wyse Management Suite < 5.2 - Unauthenticated Absolute Path Traversal
CVSS 8.2
CVE-2025-46822 HIGH
OsamaTaher Java-springboot-codebase - Path Traversal
CVE-2025-0001 MEDIUM
Abacus ERP <2024.210.16036-2022.105.15542 - Info Disclosure
CVSS 6.5
CVE-2025-0851 CRITICAL
Ai.djl API < 0.31.1 - Path Traversal
CVSS 9.8
CVE-2024-13945 MEDIUM
ABB ASPECT-Enterprise, NEXUS Series, MATRIX Series <= 3.* - Authenticated Absolute Path Traversal
CVSS 6.0
CVE-2024-48850 HIGH
ABB ASPECT-Enterprise NEXUS Series MATRIX Series <= 3.08.03 - Absolute Path Traversal
CVSS 7.2
CVE-2024-8501 HIGH
modelscope/agentscope <0.0.4 - Info Disclosure
CVSS 8.8
CVE-2024-6854 HIGH
h2o 3.46.0 - Absolute Path Traversal via Model Export Endpoint
CVSS 7.1
CVE-2024-12375 MEDIUM
automatic1111/stable-diffusion-webui git 82a973c - Absolute Path Traversal
CVSS 6.5
CVE-2024-10833 CRITICAL
db-gpt < 0.6.2 - Arbitrary File Write via Knowledge API Filename Parameter
CVSS 9.1
CVE-2024-10831 CRITICAL
db-gpt 0.6.0 - Absolute Path Traversal via File Upload Endpoint
CVSS 9.1
CVE-2024-10047 MEDIUM
parisneo/lollms-webui <latest - Path Traversal
CVSS 5.3
CVE-2024-48248 HIGH KEV
NAKIVO Backup & Replication < 11.0.0.88174 - Absolute Path Traversal via getImageByPath
CVSS 8.6
CVE-2024-6097 MEDIUM
Progress Telerik Reporting < 19.0.25.211 - Local Path Traversal via Absolute Path
CVSS 5.3
CVE-2024-57966 MEDIUM
KDE ark < 24.12.0 - Absolute Path Traversal via Archive Extraction
CVSS 5.0
CVE-2024-13161 CRITICAL KEV
Ivanti Endpoint Manager < 2022 - Unauthenticated Absolute Path Traversal
CVSS 9.8
CVE-2024-13160 CRITICAL KEV
Ivanti Endpoint Manager < 2022 SU6 - Unauthenticated Absolute Path Traversal
CVSS 9.8
CVE-2024-13159 CRITICAL KEV
Ivanti Endpoint Manager < 2022 - Unauthenticated Absolute Path Traversal
CVSS 9.8
CVE-2024-10811 CRITICAL
Ivanti Endpoint Manager < 2022 SU6 - Unauthenticated Path Traversal
CVSS 9.8
CVE-2024-56321 LOW
GoCD 18.9.0-24.4.0 - Authenticated Arbitrary Script Execution via Backup Configuration Post-Backup Script
CVSS 3.8
CVE-2024-12646 HIGH
Chunghwa Telecom topm-client - Path Traversal
CVSS 8.1
CVE-2024-12644 HIGH
Chunghwa Telecom tbm-client - CSRF & Path Traversal
CVSS 7.1
CVE-2024-12643 HIGH
Chunghwa Telecom tbm-client - Path Traversal
CVSS 8.1
Details
Vulnerabilities 126