VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (489)

page 19 of 25
  • CVE-2025-53609MedSep 9, 2025
    risk 0.33cvss 4.9epss 0.09

    A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.

  • CVE-2024-32116MedNov 12, 2024
    risk 0.33cvss 5.1epss 0.00

    Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to…

  • CVE-2023-40026MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.01

    Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external Helm charts handled by the…

  • CVE-2026-10074MedMay 29, 2026
    risk 0.32cvss 4.9epss 0.00

    DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2026-31927MedApr 17, 2026
    risk 0.32cvss 4.9epss 0.00

    Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files (e.g., /etc/shadow), enabling unauthorized SSH access when combined with debug‑setting changes.

  • CVE-2025-58463MedNov 7, 2025
    risk 0.32cvss 4.9epss 0.00

    A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in…

  • CVE-2025-9570MedSep 1, 2025
    risk 0.32cvss 4.9epss 0.01

    The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2025-46433MedApr 25, 2025
    risk 0.32cvss 4.9epss 0.01

    In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible

  • CVE-2025-32137MedApr 4, 2025
    risk 0.32cvss 4.9epss 0.01

    Relative Path Traversal vulnerability in Cristián Lávaque s2Member s2member allows Path Traversal.This issue affects s2Member: from n/a through <= 250419.

  • CVE-2024-52012MedJan 27, 2025
    risk 0.32cvss 5.4epss 0.47

    Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API.  Commonly known as a "zipslip", maliciously constructed ZIP files can use…

  • CVE-2024-9923MedOct 14, 2024
    risk 0.32cvss 4.9epss 0.01

    The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with administrator privileges to move arbitrary system files to the website root directory and access them.

  • CVE-2024-47948MedOct 8, 2024
    risk 0.32cvss 4.9epss 0.01

    In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups

  • CVE-2024-3122MedJul 1, 2024
    risk 0.32cvss 4.9epss 0.01

    CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.

  • CVE-2024-20352MedApr 3, 2024
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the…

  • CVE-2024-22398MedMar 14, 2024
    risk 0.32cvss 4.9epss 0.01

    An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attacker with administrative privileges to conduct a directory traversal attack and delete arbitrary files from the appliance…

  • CVE-2023-23778MedFeb 16, 2023
    risk 0.32cvss 4.9epss 0.01

    A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests.

  • CVE-2022-20913MedJul 22, 2022
    risk 0.32cvss 4.9epss 0.01

    A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an affected device. This vulnerability is due to insufficient input validation in the web-based management interface of Cisco Nexus Dashboard. An attacker with…

  • CVE-2022-29097MedJun 24, 2022
    risk 0.32cvss 4.9epss 0.01

    Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

  • CVE-2022-22279MedApr 13, 2022
    risk 0.32cvss 4.9epss 0.01

    A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically the SRA appliances running all 8.x, 9.0.0.5-19sv and earlier versions and…

  • CVE-2020-5284MedMar 30, 2020
    risk 0.32cvss 4.4epss 0.43

    Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets…