CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

117 vulnerabilities with CWE-36
CVE-2024-6854 HIGH
h2o-3 <3.46.0 - Path Traversal
CVSS 7.1
CVE-2024-12375 MEDIUM
Automatic1111 Stable-diffusion-webui - Absolute Path Traversal
CVSS 6.5
CVE-2024-10833 CRITICAL
Dbgpt Db-gpt < 0.6.2 - Absolute Path Traversal
CVSS 9.1
CVE-2024-10831 CRITICAL
Dbgpt Db-gpt - Absolute Path Traversal
CVSS 9.1
CVE-2024-10047 MEDIUM
parisneo/lollms-webui <latest - Path Traversal
CVSS 5.3
CVE-2024-48248 HIGH KEV
Nakivo Backup & Replication Director - Absolute Path Traversal
CVSS 8.6
CVE-2024-6097 MEDIUM
Progress Telerik Reporting < 19.0.25.211 - Path Traversal
CVSS 5.3
CVE-2024-57966 MEDIUM
KDE ark <24.12.0 - Path Traversal
CVSS 5.0
CVE-2024-13161 CRITICAL KEV
Ivanti EPM - Path Traversal
CVSS 9.8
CVE-2024-13160 CRITICAL KEV
Ivanti EPM - Path Traversal
CVSS 9.8
CVE-2024-13159 CRITICAL KEV
Ivanti EPM - Path Traversal
CVSS 9.8
CVE-2024-10811 CRITICAL
Ivanti Endpoint Manager < 2022 - Path Traversal
CVSS 9.8
CVE-2024-56321 LOW
Thoughtworks Gocd < 24.5.0 - Absolute Path Traversal
CVSS 3.8
CVE-2024-12646 HIGH
Chunghwa Telecom topm-client - Path Traversal
CVSS 8.1
CVE-2024-12644 HIGH
Chunghwa Telecom tbm-client - CSRF & Path Traversal
CVSS 7.1
CVE-2024-12643 HIGH
Chunghwa Telecom tbm-client - Path Traversal
CVSS 8.1
CVE-2024-51549 CRITICAL
ABB ASPECT <3.08.02, NEXUS Series <3.08.02, MATRIX Series <3.08.02 ...
CVSS 10.0
CVE-2024-11978 HIGH
DreamMaker - Path Traversal
CVSS 7.5
CVE-2024-10651 MEDIUM
IDExpert - Info Disclosure
CVSS 4.9
CVE-2024-47883 CRITICAL
Openrefine Butterfly < 1.2.6 - SSRF
CVSS 9.1
CVE-2024-20379 MEDIUM
Cisco Secure Firewall Management Center - Info Disclosure
CVSS 6.5
CVE-2024-9924 CRITICAL
OAKlouds - Info Disclosure
CVSS 9.8
CVE-2024-45291 MEDIUM
PHPSpreadsheet - SSRF
CVSS 6.3
CVE-2024-45290 HIGH
PHPSpreadsheet - XSS
CVSS 7.7
CVE-2024-8497 HIGH
Franklin Fueling Systems TS-550 EVO <2.26.4.8967 - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 117