VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 10 of 25
  • CVE-2021-29101HigMay 5, 2021
    risk 0.49cvss 7.5epss 0.02

    ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow an unauthenticated, remote attacker to perform directory traversal attacks and read arbitrary files on the system.

  • CVE-2020-7008HigApr 3, 2020
    risk 0.49cvss 7.5epss 0.02

    VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow input passed in the URL that is not properly verified before use, which may allow an attacker to read arbitrary files from local resources.

  • CVE-2019-13408HigAug 29, 2019
    risk 0.49cvss 7.5epss 0.02

    A relative path traversal vulnerability found in Advan VD-1 firmware versions up to 230. It allows attackers to download arbitrary files via url cgibin/ExportSettings.cgi?Download=filepath, without any authentication.

  • CVE-2026-44941HigJul 2, 2026
    risk 0.48cvss 8.4epss 0.01

    A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

  • CVE-2025-52922HigJun 23, 2025
    risk 0.48cvss 7.4epss 0.00

    Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access to the admin panel could abuse this to: (1) fully map the filesystem structure via the /api/file_manager/files?base_folder= endpoint, (2) create arbitrary…

  • CVE-2024-43454HigSep 10, 2024
    risk 0.48cvss 7.1epss 0.22

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

  • CVE-2021-34605HigMay 11, 2022
    risk 0.48cvss 7.3epss 0.02

    A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitrary file write privilege when opening a specially-crafted project file. This vulnerability can be triggered by manually opening an infected project file, or by…

  • CVE-2020-5405MedMar 5, 2020
    risk 0.48cvss 6.5epss 0.69

    Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a…

  • CVE-2026-41046HigJun 22, 2026
    risk 0.47cvss 7.3epss 0.00

    A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.

  • CVE-2026-7404HigApr 29, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_prompt of the file src/mcpo_simple_server/services/prompt_manager/base_manager.py. This manipulation of the argument detail causes relative path traversal. It…

  • CVE-2026-32725HigMar 31, 2026
    risk 0.47cvss 8.3epss 0.01

    SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp is vulnerable to an authorization bypass when processing path-based scopes in tokens. The library normalizes the scope path from the token before…

  • CVE-2025-68472HigJan 12, 2026
    risk 0.47cvss 8.1epss 0.20

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing…

  • CVE-2025-55752HigOct 27, 2025
    risk 0.47cvss 7.5epss 0.67

    Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the …

  • CVE-2025-53779HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.03

    Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-27791HigApr 15, 2025
    risk 0.47cvss epss 0.00

    Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to…

  • CVE-2025-26349HigFeb 12, 2025
    risk 0.47cvss 7.2epss 0.03

    A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite arbitrary files via crafted HTTP requests.

  • CVE-2021-32803HigAug 3, 2021
    risk 0.47cvss 8.2epss 0.08

    The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location would be modified by a symbolic link is not…

  • CVE-2026-53416HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.

  • CVE-2026-66881HigAug 5, 2026
    risk 0.46cvss 8.1epss 0.00

    Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content to an arbitrary path. A .livemd notebook can declare file_entries metadata, each entry carrying a name. Every path that creates a…

  • CVE-2026-34026HigJun 15, 2026
    risk 0.46cvss epss 0.00

    Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without…