VYPR

CWE-24

Path Traversal: '../filedir'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (116)

page 1 of 6
  • CVE-2026-39813CriApr 14, 2026
    risk 0.66cvss 9.8epss 0.23

    A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

  • CVE-2022-38129CriAug 10, 2022
    risk 0.65cvss 9.8epss 0.19

    A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to the SMS host.

  • CVE-2025-54769HigJul 29, 2025
    risk 0.60cvss 8.8epss 0.03

    An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an…

  • CVE-2025-61318CriDec 8, 2025
    risk 0.59cvss 9.1epss 0.01

    Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability. This vulnerability stems from the admin/template.php component and the admin/plugin.php component. They fail to perform path verification and dangerous code filtering for deletion parameters, allowing attackers to…

  • CVE-2025-27920HigKEVMay 5, 2025
    risk 0.59cvss 7.2epss 0.02

    Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or…

  • CVE-2023-6699CriJan 11, 2024
    risk 0.59cvss 9.1epss 0.01

    The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the…

  • CVE-2025-60344HigOct 21, 2025
    risk 0.57cvss 8.6epss 0.10

    A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate input parameters used for file or directory path resolution (e.g., via sequences such as “../”). Successful exploitation may allow access…

  • CVE-2024-23657HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined with a lack of Origin checks on the…

  • CVE-2026-66140HigJul 24, 2026
    risk 0.55cvss 8.4epss 0.00

    Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.

  • CVE-2026-49103CriMay 27, 2026
    risk 0.54cvss epss 0.00

    Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

  • CVE-2023-53691HigOct 22, 2025
    risk 0.54cvss 8.3epss 0.01

    Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2023-06-25 allows file upload via /center/api/files directory traversal, as exploited in the wild in 2024 and 2025.

  • CVE-2025-63298HigOct 30, 2025
    risk 0.53cvss 8.2epss 0.00

    A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request,…

  • CVE-2021-33036HigJun 15, 2022
    risk 0.51cvss 8.8epss 0.04

    In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 or higher.

  • CVE-2025-53513HigJul 8, 2025
    risk 0.50cvss 8.8epss 0.01

    The /charms endpoint on a Juju controller lacked sufficient authorization checks, allowing any user with an account on the controller to upload a charm. Uploading a malicious charm that exploits a Zip Slip vulnerability could allow an attacker to gain access to a machine running…

  • CVE-2026-28427HigMar 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves static files for installed plugins but does not properly sanitize path components. By including ../ sequences in the request path, an attacker can traverse outside…

  • CVE-2025-67364HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.01

    fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and…

  • CVE-2025-51661HigNov 19, 2025
    risk 0.49cvss 7.5epss 0.01

    A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage.save_file method in core/storage.py uses filenames from user input without validation to construct…

  • CVE-2024-22079HigMar 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.

  • CVE-2020-7882HigNov 22, 2021
    risk 0.49cvss 7.5epss 0.01

    Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')

  • CVE-2026-40318HigApr 16, 2026
    risk 0.48cvss 8.5epss 0.00

    SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject…