CWE-36

Absolute Path Traversal

Parent: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

117 vulnerabilities with CWE-36
CVE-2024-8778 MEDIUM
OMFLOW - Info Disclosure
CVSS 6.5
CVE-2024-7323 MEDIUM
Digiwin Easyflow .net < 6.6.17 - Path Traversal
CVSS 6.5
CVE-2024-28806 HIGH
Italtel I-mcs Nfv - Absolute Path Traversal
CVSS 7.5
CVE-2024-20401 CRITICAL
Cisco Secure Email Gateway - File Overwrite
CVSS 9.8
CVE-2024-6250 HIGH
parisneo/lollms-webui <9.6 - Path Traversal
CVSS 7.5
CVE-2024-33620 HIGH
ID Link Manager/FUJITSU Software TIME CREATOR - Path Traversal
CVSS 8.6
CVE-2024-4881 HIGH
Lollms < 5.9.0 - Path Traversal
CVSS 7.5
CVE-2024-2548 HIGH
Lollms Web UI < 9.5 - Path Traversal
CVSS 7.5
CVE-2024-2362 CRITICAL
Lollms Web UI - Path Traversal
CVSS 9.1
CVE-2024-29053 HIGH
Microsoft Defender For Iot < 24.1.3 - Path Traversal
CVSS 8.8
CVE-2024-21323 HIGH
Microsoft Defender For Iot < 24.1.3 - Absolute Path Traversal
CVSS 8.8
CVE-2024-1703 LOW
Crmeb - Path Traversal
CVSS 3.5
CVE-2023-41830 MEDIUM
Ready For - Path Traversal
CVSS 6.5
CVE-2023-50955 LOW
IBM Infosphere Information Server - Path Traversal
CVSS 2.4
CVE-2023-5390 MEDIUM
Honeywell Controledge Unit Operations... - Path Traversal
CVSS 5.3
CVE-2023-30970 MEDIUM
Gotham Table service & Forward App - Path Traversal
CVSS 6.5
CVE-2023-5115 MEDIUM
Ansible - Path Traversal
CVSS 6.3
CVE-2023-36786 HIGH
Skype for Business - RCE
CVSS 7.2
CVE-2023-5022 MEDIUM
Dedecms < 5.7.100 - Absolute Path Traversal
CVSS 5.5
CVE-2023-40597 HIGH
Splunk Enterprise <8.2.12, 9.0.6, 9.1.1 - Path Traversal
CVSS 7.8
CVE-2023-4172 MEDIUM
Cdwanjiang Flash Flood Disaster Monit... - Path Traversal
CVSS 4.3
CVE-2023-3765 CRITICAL
Lfprojects Mlflow < 2.5.0 - Absolute Path Traversal
CVSS 10.0
CVE-2023-34135 MEDIUM
SonicWall GMS & Analytics <9.3.2-SP1 - Path Traversal
CVSS 6.5
CVE-2023-32054 HIGH
Microsoft Windows 10 1507 < 10.0.10240.20048 - Absolute Path Traversal
CVSS 7.3
CVE-2023-2765 MEDIUM
Weaver E-office - Absolute Path Traversal
CVSS 4.3
Details
Vulnerabilities 117