CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (525)
page 18 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-48681 | Med | 0.38 | 5.9 | 0.01 | Jun 4, 2026 | OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image. | ||
| CVE-2025-59336 | Med | 0.38 | — | 0.00 | Sep 16, 2025 | Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec… | ||
| CVE-2025-49466 | Med | 0.38 | 5.8 | 0.01 | Jun 5, 2025 | aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part, | ||
| CVE-2022-34836 | Med | 0.38 | 5.9 | 0.01 | Aug 24, 2022 | Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities… | ||
| CVE-2018-18990 | Med | 0.38 | 5.3 | 0.39 | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process. | ||
| CVE-2026-77113 | Med | 0.37 | — | 0.00 | Aug 20, 2026 | Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files. | ||
| CVE-2026-62843 | Med | 0.37 | 6.8 | 0.00 | Jul 15, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as… | ||
| CVE-2025-24819 | Med | 0.37 | 5.7 | 0.00 | Apr 7, 2026 | Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application. | ||
| CVE-2025-59456 | Med | 0.37 | 5.5 | 0.13 | Sep 17, 2025 | In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload | ||
| CVE-2024-25944 | Med | 0.37 | 5.7 | 0.01 | Mar 29, 2024 | Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running… | ||
| CVE-2024-24942 | Med | 0.37 | 5.3 | 0.32 | Feb 6, 2024 | In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives | ||
| CVE-2023-23784 | Med | 0.37 | 5.7 | 0.01 | Feb 16, 2023 | A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests. | ||
| CVE-2022-1648 | Med | 0.37 | 5.7 | 0.01 | Jul 26, 2022 | Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running… | ||
| CVE-2026-21082 | Med | 0.36 | 5.5 | 0.00 | Aug 10, 2026 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | ||
| CVE-2026-41612 | Med | 0.36 | 5.5 | 0.01 | May 12, 2026 | Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally. | ||
| CVE-2024-46664 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests. | ||
| CVE-2024-32115 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2025 | A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests. | ||
| CVE-2024-43614 | Med | 0.36 | 5.5 | 0.01 | Oct 8, 2024 | Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally. | ||
| CVE-2023-23391 | Med | 0.36 | 5.5 | 0.01 | Mar 14, 2023 | Office for Android Spoofing Vulnerability | ||
| CVE-2023-20040 | Med | 0.36 | 5.5 | 0.01 | Jan 20, 2023 | A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the attacker must be a… |
- risk 0.38cvss 5.9epss 0.01
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.
- risk 0.38cvss —epss 0.00
Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix runtime files. Package names like ../../package are not properly filtered and pass the validity check of the rockspec…
- risk 0.38cvss 5.8epss 0.01
aerc before 93bec0d allows directory traversal in commands/msgview/open.go because of direct path concatenation of the name of an attachment part,
- risk 0.38cvss 5.9epss 0.01
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities…
- risk 0.38cvss 5.3epss 0.39
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.
- risk 0.37cvss —epss 0.00
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
- risk 0.37cvss 6.8epss 0.00
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as…
- risk 0.37cvss 5.7epss 0.00
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.
- risk 0.37cvss 5.5epss 0.13
In JetBrains TeamCity before 2025.07.2 path traversal was possible during project archive upload
- risk 0.37cvss 5.7epss 0.01
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, to gain unauthorized access to the files stored on the server filesystem, with the privileges of the running…
- risk 0.37cvss 5.3epss 0.32
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
- risk 0.37cvss 5.7epss 0.01
A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests.
- risk 0.37cvss 5.7epss 0.01
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a .php file outside the intended images directory which is restricted to execute the .php file. The impact could lead to a Remote Code Execution with running…
- risk 0.36cvss 5.5epss 0.00
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
- risk 0.36cvss 5.5epss 0.01
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
- risk 0.36cvss 5.5epss 0.01
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.
- risk 0.36cvss 5.5epss 0.01
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTPs requests.
- risk 0.36cvss 5.5epss 0.01
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
- risk 0.36cvss 5.5epss 0.01
Office for Android Spoofing Vulnerability
- risk 0.36cvss 5.5epss 0.01
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote attacker to cause a denial of service (DoS) on an affected system that is running as the root user. To exploit this vulnerability, the attacker must be a…