VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 17 of 25
  • CVE-2022-1648MedJul 26, 2022
    risk 0.37cvss 5.7epss 0.01

    Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running…

  • CVE-2026-41612MedMay 12, 2026
    risk 0.36cvss 5.5epss 0.01

    Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.

  • CVE-2024-46664MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.

  • CVE-2024-32115MedJan 14, 2025
    risk 0.36cvss 5.5epss 0.01

    A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.

  • CVE-2024-43614MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.01

    Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.

  • CVE-2023-23391MedMar 14, 2023
    risk 0.36cvss 5.5epss 0.01

    Office for Android Spoofing Vulnerability

  • CVE-2023-20040MedJan 20, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the attacker must be a…

  • CVE-2022-34378MedSep 2, 2022
    risk 0.36cvss 5.5epss 0.00

    Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to denial of service.

  • CVE-2020-1904MedOct 6, 2020
    risk 0.36cvss 5.5epss 0.01

    A path validation issue in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have allowed for directory traversal overwriting files when sending specially crafted docx, xlsx, and pptx files as attachments to messages.

  • CVE-2019-0074MedOct 9, 2019
    risk 0.36cvss 5.5epss 0.00

    A path traversal vulnerability in NFX150 Series and QFX10K Series, EX9200 Series, MX Series and PTX Series devices with Next-Generation Routing Engine (NG-RE) allows a local authenticated user to read sensitive system files. This issue only affects NFX150 Series and QFX10K…

  • CVE-2025-48977MedMay 28, 2026
    risk 0.35cvss 6.5epss 0.01

    Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the server with "cmd=log" command and a log path crafted in a certain way. This issue affects Apache Ignite: from 2.0.0 through 2.17.0. Users are recommended to…

  • CVE-2026-39378MedApr 21, 2026
    risk 0.35cvss 6.5epss 0.00

    The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to various other formats via Jinja templates. In versions 6.5 through 7.17.0, when `HTMLExporter.embed_images=True`, nbconvert's markdown renderer allows arbitrary file read via path traversal in image references.…

  • CVE-2026-23890MedJan 26, 2026
    risk 0.35cvss 6.5epss 0.00

    pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validation, and after scope…

  • CVE-2026-23888MedJan 26, 2026
    risk 0.35cvss 6.5epss 0.00

    pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../`…

  • CVE-2025-8464MedAug 16, 2025
    risk 0.35cvss 5.3epss 0.01

    The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files…

  • CVE-2025-46002MedJul 18, 2025
    risk 0.35cvss 6.5epss 0.02

    An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.

  • CVE-2025-24343MedApr 30, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attacker to write arbitrary files in arbitrary file system paths via a crafted HTTP request.

  • CVE-2025-43016MedApr 25, 2025
    risk 0.35cvss 5.4epss 0.00

    In JetBrains Rider before 2025.1.2 custom archive unpacker allowed arbitrary file overwrite during remote debug session

  • CVE-2024-6483MedMar 20, 2025
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used to specify log/metadata…

  • CVE-2025-1599MedFeb 24, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/app/profile_crud.php. The manipulation of the argument old_cat_img leads to path traversal:…