CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (489)
page 6 of 25| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55747 | Cri | 0.52 | 9.1 | 0.02 | Sep 3, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7. | ||
| CVE-2025-31493 | Cri | 0.52 | 9.1 | 0.01 | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends… | ||
| CVE-2025-30159 | Cri | 0.52 | 9.1 | 0.01 | May 13, 2025 | Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet name that depends on request… | ||
| CVE-2024-47051 | Cri | 0.52 | 9.1 | 0.02 | Feb 26, 2025 | This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution (RCE) via Asset Upload: A Remote Code Execution vulnerability has been identified… | ||
| CVE-2024-54154 | Hig | 0.52 | 8.0 | 0.01 | Dec 4, 2024 | In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox | ||
| CVE-2024-45731 | Hig | 0.52 | 8.0 | 0.01 | Oct 14, 2024 | In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk… | ||
| CVE-2024-2053 | Hig | 0.52 | 7.5 | 0.45 | Mar 21, 2024 | The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web… | ||
| CVE-2020-8570 | Cri | 0.52 | 9.1 | 0.04 | Jan 21, 2021 | Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system… | ||
| CVE-2019-11826 | Hig | 0.52 | 8.0 | 0.02 | Jun 30, 2019 | Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter. | ||
| CVE-2026-65810 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-41280 | Hig | 0.51 | 7.8 | 0.00 | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is… | ||
| CVE-2025-62552 | Hig | 0.51 | 7.8 | 0.01 | Dec 9, 2025 | Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-10203 | Hig | 0.51 | 7.8 | 0.00 | Sep 15, 2025 | Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent… | ||
| CVE-2023-35359 | Hig | 0.51 | 7.8 | 0.10 | Aug 8, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-34394 | Hig | 0.51 | 7.8 | 0.00 | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service… | ||
| CVE-2022-42470 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2023 | A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | ||
| CVE-2023-23379 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2022-1373 | Hig | 0.51 | 7.2 | 0.13 | Aug 17, 2022 | The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"… | ||
| CVE-2021-20040 | Hig | 0.51 | 7.5 | 0.26 | Dec 8, 2021 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | ||
| CVE-2021-29100 | Hig | 0.51 | 7.8 | 0.01 | May 5, 2021 | A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user… |
- risk 0.52cvss 9.1epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10.6, configuration files are accessible through the webjars API. This is fixed in version 16.10.7.
- risk 0.52cvss 9.1epss 0.01
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `collection()` helper or `$kirby->collection()` method with a dynamic collection name (such as a collection name that depends…
- risk 0.52cvss 9.1epss 0.01
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 affects all Kirby sites that use the `snippet()` helper or `$kirby->snippet()` method with a dynamic snippet name (such as a snippet name that depends on request…
- risk 0.52cvss 9.1epss 0.02
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution (RCE) via Asset Upload: A Remote Code Execution vulnerability has been identified…
- risk 0.52cvss 8.0epss 0.01
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
- risk 0.52cvss 8.0epss 0.01
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 folder, when Splunk…
- risk 0.52cvss 7.5epss 0.45
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web…
- risk 0.52cvss 9.1epss 0.04
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system…
- risk 0.52cvss 8.0epss 0.02
Relative path traversal vulnerability in SYNO.PhotoTeam.Upload.Item in Synology Moments before 1.3.0-0691 allows remote authenticated users to upload arbitrary files via the name parameter.
- risk 0.51cvss 7.8epss 0.00
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is…
- risk 0.51cvss 7.8epss 0.01
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent…
- risk 0.51cvss 7.8epss 0.10
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service…
- risk 0.51cvss 7.8epss 0.00
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
- risk 0.51cvss 7.8epss 0.00
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.51cvss 7.2epss 0.13
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"…
- risk 0.51cvss 7.5epss 0.26
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
- risk 0.51cvss 7.8epss 0.01
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user…