VYPR

CWE-23

Relative Path Traversal

BaseDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-139 · CAPEC-76

CVEs mapped to this weakness (525)

page 8 of 27
  • CVE-2024-47637HigOct 16, 2024
    risk 0.50cvss 8.8epss 0.01

    Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through <= 6.4.1.

  • CVE-2024-0520HigJun 6, 2024
    risk 0.50cvss 8.8epss 0.02

    A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.http_dataset_source.py` module. Specifically, when loading a dataset from a…

  • CVE-2024-35186HigMay 23, 2024
    risk 0.50cvss 8.8epss 0.01

    gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files anywhere writable by the application. This vulnerability leads…

  • CVE-2022-1661HigJun 2, 2022
    risk 0.50cvss 7.5epss 0.16

    The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating system files.

  • CVE-2020-25150HigApr 14, 2022
    risk 0.50cvss 7.6epss 0.02

    A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker…

  • CVE-2021-43555HigNov 19, 2021
    risk 0.50cvss 7.3epss 0.38

    mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or…

  • CVE-2019-18338HigDec 12, 2019
    risk 0.50cvss 7.7epss 0.03

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains a directory traversal vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An…

  • CVE-2026-93468HigSep 18, 2026
    risk 0.49cvss 7.5epss 0.00

    The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

  • CVE-2026-78212HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.01

    4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Relative Path Traversal flaw to download arbitrary system files.

  • CVE-2026-63043HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] …

  • CVE-2026-18907HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

  • CVE-2026-10073HigMay 29, 2026
    risk 0.49cvss 7.5epss 0.00

    DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2025-41271HigMay 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to read arbitrary files from the device.

  • CVE-2026-8361HigMay 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome

  • CVE-2026-43533HigMay 5, 2026
    risk 0.49cvss 8.6epss 0.00

    OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to reference host-local paths outside the intended media storage boundary. Attackers can craft malicious reply text containing media tags to disclose arbitrary local…

  • CVE-2026-30345HigMar 18, 2026
    risk 0.49cvss 7.5epss 0.00

    A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitrary files outside the intended directories via supplying a crafted import.

  • CVE-2026-27202HigFeb 21, 2026
    risk 0.49cvss 7.5epss 0.01

    GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.

  • CVE-2026-1022HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.

  • CVE-2025-67366HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.01

    @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path…

  • CVE-2025-15225HigDec 29, 2025
    risk 0.49cvss 7.5epss 0.01

    WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to read arbitrary system files.