VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (525)

page 20 of 27
  • CVE-2024-24938MedFeb 6, 2024
    risk 0.35cvss 5.3epss 0.01

    In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation

  • CVE-2023-29189MedApr 11, 2023
    risk 0.35cvss 5.4epss 0.00

    SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful…

  • CVE-2020-3597MedOct 8, 2020
    risk 0.35cvss 5.4epss 0.01

    A vulnerability in the configuration restore feature of Cisco Nexus Data Broker software could allow an unauthenticated, remote attacker to perform a directory traversal attack on an affected device. The vulnerability is due to insufficient validation of configuration backup…

  • CVE-2019-13944MedDec 12, 2019
    risk 0.35cvss 5.3epss 0.02

    A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet…

  • CVE-2026-33206MedMar 27, 2026
    risk 0.34cvss 6.3epss 0.00

    calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.6.0, a path traversal vulnerability exists in Calibre' handling of images in Markdown and other similar text-based files allowing an attacker to include…

  • CVE-2025-40605MedNov 20, 2025
    risk 0.34cvss 5.3epss 0.00

    A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.

  • CVE-2025-13199MedNov 15, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in code-projects Email Logging Interface 2.0. Affected is an unknown function of the file signup.cpp. The manipulation of the argument Username results in path traversal: '../filedir'. The attack is only possible with local access. The exploit has been…

  • CVE-2025-44163MedJun 27, 2025
    risk 0.34cvss 6.3epss 0.01

    RaspAP raspap-webgui 3.3.1 is vulnerable to Directory Traversal in ajax/networking/get_wgkey.php. An authenticated attacker can send a crafted POST request with a path traversal payload in the `entity` parameter to overwrite arbitrary files writable by the web server via abuse…

  • CVE-2025-22859MedMay 13, 2025
    risk 0.34cvss 5.3epss 0.01

    A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.

  • CVE-2024-8510MedMar 17, 2025
    risk 0.34cvss 5.3epss 0.00

    N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.

  • CVE-2024-47949MedOct 8, 2024
    risk 0.34cvss 4.9epss 0.23

    In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location

  • CVE-2024-9405MedOct 1, 2024
    risk 0.34cvss 5.3epss 0.00

    An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via the absolute path of a file located in the same directory or…

  • CVE-2022-30299MedFeb 16, 2023
    risk 0.34cvss 5.3epss 0.00

    A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions may allow an authenticated attacker to retrieve specific parts of files from the underlying file…

  • CVE-2022-42892MedNov 17, 2022
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder accessible to the account assigned to…

  • CVE-2016-20023MedDec 5, 2025
    risk 0.33cvss 5.0epss 0.00

    In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.

  • CVE-2025-53609MedSep 9, 2025
    risk 0.33cvss 4.9epss 0.09

    A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests.

  • CVE-2024-32116MedNov 12, 2024
    risk 0.33cvss 5.1epss 0.00

    Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to…

  • CVE-2023-40026MedSep 27, 2023
    risk 0.33cvss 5.0epss 0.01

    Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at least in v0.1.0, but likely in any version using Helm before 2.3), using a specifically-crafted Helm file could reference external Helm charts handled by the…

  • CVE-2026-87747MedSep 9, 2026
    risk 0.32cvss 4.9epss 0.00

    The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2026-10074MedMay 29, 2026
    risk 0.32cvss 4.9epss 0.00

    DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.