VYPR

CWE-25

Path Traversal: '/../filedir'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/../" sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (13)

  • CVE-2022-20775HigKEVSep 30, 2022
    risk 0.64cvss 7.8epss 0.12

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running…

  • CVE-2025-68916CriDec 24, 2025
    risk 0.59cvss 9.1epss 0.02

    Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code execution.

  • CVE-2024-56327CriDec 19, 2024
    risk 0.57cvss 9.8epss 0.00

    pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w. All details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions…

  • CVE-2022-20818HigSep 30, 2022
    risk 0.51cvss 7.8epss 0.01

    Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit these…

  • CVE-2023-6947HigDec 10, 2024
    risk 0.50cvss 7.7epss 0.01

    The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.26. This makes it possible for authenticated attackers, with contributor level or higher to read the contents of arbitrary folders…

  • CVE-2024-2442HigMar 19, 2024
    risk 0.49cvss 7.5epss 0.01

    Franklin Fueling System EVO 550 and EVO 5000 are vulnerable to a Path Traversal vulnerability that could allow an attacker to access sensitive files on the system.

  • CVE-2023-6919HigJan 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '/../filedir' vulnerability in Biges Safe Life Technologies Electronics Inc. VGuard allows Absolute Path Traversal. This issue affects VGuard: before V500.0003.R008.4011.C0012.B351.C.

  • CVE-2023-6118HigNov 23, 2023
    risk 0.49cvss 7.5epss 0.01

    Path Traversal: '/../filedir' vulnerability in Neutron IP Camera allows Absolute Path Traversal. This issue affects IP Camera: before b1130.1.0.1.

  • CVE-2025-0225MedJan 5, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to…

  • CVE-2026-23877MedJan 19, 2026
    risk 0.21cvss 4.3epss 0.01

    Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary…

  • CVE-2025-58286LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-52138HigFeb 5, 2024
    risk 0.00cvss 8.2epss 0.02

    Engrampa is an archive manager for the MATE environment. Engrampa is found to be vulnerable to a Path Traversal vulnerability that can be leveraged to achieve full Remote Command Execution (RCE) on the target. While handling CPIO archives, the Engrampa Archive manager follows…

  • CVE-2023-52076HigJan 25, 2024
    risk 0.00cvss 8.5epss 0.01

    Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the…