CWE-23
Relative Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-139 · CAPEC-76
CVEs mapped to this weakness (525)
page 7 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65810 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2025-41280 | Hig | 0.51 | 7.8 | 0.00 | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is… | ||
| CVE-2025-62552 | Hig | 0.51 | 7.8 | 0.01 | Dec 9, 2025 | Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-10203 | Hig | 0.51 | 7.8 | 0.00 | Sep 15, 2025 | Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent… | ||
| CVE-2023-35359 | Hig | 0.51 | 7.8 | 0.10 | Aug 8, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-34394 | Hig | 0.51 | 7.8 | 0.00 | Jul 19, 2023 | In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service… | ||
| CVE-2022-42470 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2023 | A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | ||
| CVE-2023-23379 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | ||
| CVE-2022-1373 | Hig | 0.51 | 7.2 | 0.13 | Aug 17, 2022 | The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"… | ||
| CVE-2021-20040 | Hig | 0.51 | 7.5 | 0.25 | Dec 8, 2021 | A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances. | ||
| CVE-2021-29100 | Hig | 0.51 | 7.8 | 0.01 | May 5, 2021 | A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user… | ||
| CVE-2020-5237 | Hig | 0.51 | 8.8 | 0.04 | Feb 5, 2020 | Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to… | ||
| CVE-2026-15913 | Hig | 0.50 | 7.7 | 0.00 | Sep 9, 2026 | In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read. | ||
| CVE-2026-85199 | Hig | 0.50 | — | 0.01 | Sep 3, 2026 | Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or… | ||
| CVE-2026-81849 | Hig | 0.50 | 8.8 | 0.01 | Aug 28, 2026 | Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary… | ||
| CVE-2026-55100 | Hig | 0.50 | — | 0.00 | Jul 31, 2026 | hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using… | ||
| CVE-2026-14903 | Hig | 0.50 | 7.7 | 0.01 | Jul 14, 2026 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. | ||
| CVE-2026-25707 | Hig | 0.50 | 8.8 | 0.01 | Jun 29, 2026 | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation. | ||
| CVE-2025-54531 | Hig | 0.50 | 7.7 | 0.00 | Jul 28, 2025 | In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | ||
| CVE-2025-32017 | Hig | 0.50 | 8.8 | 0.01 | Apr 8, 2025 | Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is… |
- risk 0.51cvss 7.8epss 0.00
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured and file compression is…
- risk 0.51cvss 7.8epss 0.01
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file. This vulnerability affects Digilent…
- risk 0.51cvss 7.8epss 0.10
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service…
- risk 0.51cvss 7.8epss 0.00
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe.
- risk 0.51cvss 7.8epss 0.00
Microsoft Defender for IoT Elevation of Privilege Vulnerability
- risk 0.51cvss 7.2epss 0.13
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration"…
- risk 0.51cvss 7.5epss 0.25
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as a 'nobody' user. This vulnerability affected SMA 200, 210, 400, 410 and 500v appliances.
- risk 0.51cvss 7.8epss 0.01
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creation on an affected system through crafted input. An attacker could exploit this vulnerability to gain arbitrary code execution under security context of the user…
- risk 0.51cvss 8.8epss 0.04
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to…
- risk 0.50cvss 7.7epss 0.00
In versions prior to 7.10.2 a path traversal vulnerability in the /attachRemoteFiles endpoint of Fortra's GoAnywhere MFT allows Web Users with both Secure Folders and Secure Mail permissions to escape their sandboxed home directory, achieving arbitrary file read.
- risk 0.50cvss —epss 0.01
Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or…
- risk 0.50cvss 8.8epss 0.01
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary…
- risk 0.50cvss —epss 0.00
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using…
- risk 0.50cvss 7.7epss 0.01
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
- risk 0.50cvss 8.8epss 0.01
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
- risk 0.50cvss 7.7epss 0.00
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
- risk 0.50cvss 8.8epss 0.01
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able to craft management API request that exploit a path traversal vulnerability to upload files into a incorrect location. The issue affects Umbraco 14+ and is…