CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (489)
page 10 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-29101 | Hig | 0.49 | 7.5 | 0.02 | May 5, 2021 | ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system. | ||
| CVE-2020-7008 | Hig | 0.49 | 7.5 | 0.02 | Apr 3, 2020 | VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources. | ||
| CVE-2019-13408 | Hig | 0.49 | 7.5 | 0.02 | Aug 29, 2019 | A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication. | ||
| CVE-2026-44941 | Hig | 0.48 | 8.4 | 0.01 | Jul 2, 2026 | A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root. | ||
| CVE-2025-52922 | Hig | 0.48 | 7.4 | 0.00 | Jun 23, 2025 | Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary… | ||
| CVE-2024-43454 | Hig | 0.48 | 7.1 | 0.22 | Sep 10, 2024 | Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | ||
| CVE-2021-34605 | Hig | 0.48 | 7.3 | 0.02 | May 11, 2022 | A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by… | ||
| CVE-2020-5405 | Med | 0.48 | 6.5 | 0.69 | Mar 5, 2020 | Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a… | ||
| CVE-2026-41046 | Hig | 0.47 | 7.3 | 0.00 | Jun 22, 2026 | A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root. | ||
| CVE-2026-7404 | — | Hig | 0.47 | 7.3 | 0.01 | Apr 29, 2026 | A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It… | |
| CVE-2026-32725 | Hig | 0.47 | 8.3 | 0.01 | Mar 31, 2026 | SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before… | ||
| CVE-2025-68472 | Hig | 0.47 | 8.1 | 0.20 | Jan 12, 2026 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing… | ||
| CVE-2025-55752 | Hig | 0.47 | 7.5 | 0.67 | Oct 27, 2025 | Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the … | ||
| CVE-2025-53779 | Hig | 0.47 | 7.2 | 0.03 | Aug 12, 2025 | Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-27791 | Hig | 0.47 | — | 0.00 | Apr 15, 2025 | Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to… | ||
| CVE-2025-26349 | Hig | 0.47 | 7.2 | 0.03 | Feb 12, 2025 | A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests. | ||
| CVE-2021-32803 | Hig | 0.47 | 8.2 | 0.08 | Aug 3, 2021 | The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not… | ||
| CVE-2026-53416 | Hig | 0.46 | 7.1 | 0.00 | Aug 11, 2026 | Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. | ||
| CVE-2026-66881 | Hig | 0.46 | 8.1 | 0.00 | Aug 5, 2026 | Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a… | ||
| CVE-2026-34026 | Hig | 0.46 | — | 0.00 | Jun 15, 2026 | Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without… |
- risk 0.49cvss 7.5epss 0.02
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.
- risk 0.49cvss 7.5epss 0.02
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.
- risk 0.49cvss 7.5epss 0.02
A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.
- risk 0.48cvss 8.4epss 0.01
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
- risk 0.48cvss 7.4epss 0.00
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary…
- risk 0.48cvss 7.1epss 0.22
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.02
A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by…
- risk 0.48cvss 6.5epss 0.69
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a…
- risk 0.47cvss 7.3epss 0.00
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.
- risk 0.47cvss 7.3epss 0.01
A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It…
- risk 0.47cvss 8.3epss 0.01
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before…
- risk 0.47cvss 8.1epss 0.20
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing…
- risk 0.47cvss 7.5epss 0.67
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the …
- risk 0.47cvss 7.2epss 0.03
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss —epss 0.00
Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to…
- risk 0.47cvss 7.2epss 0.03
A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.
- risk 0.47cvss 8.2epss 0.08
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not…
- risk 0.46cvss 7.1epss 0.00
Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.
- risk 0.46cvss 8.1epss 0.00
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a…
- risk 0.46cvss —epss 0.00
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without…