VYPR

CWE-27

Path Traversal: 'dir/../../filename'

VariantDraft

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize multiple internal "../" sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (28)

page 2 of 2
  • CVE-2026-20018MedMar 4, 2026
    risk 0.38cvss 5.9epss 0.00

    A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrative privileges to write arbitrary files as root on the…

  • CVE-2024-7458MedAug 4, 2024
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file…

  • CVE-2024-25828MedFeb 22, 2024
    risk 0.32cvss 4.9epss 0.01

    cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

  • CVE-2025-58292LowOct 11, 2025
    risk 0.21cvss 3.3epss 0.00

    Denial of service (DoS) vulnerability in the office service. Successful exploitation of this vulnerability may affect availability.

  • CVE-2025-58761HigSep 9, 2025
    risk 0.00cvss 8.6epss 0.01

    Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem.…

  • CVE-2023-52076HigJan 25, 2024
    risk 0.00cvss 8.5epss 0.01

    Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing arbitrary files anywhere on the…

  • CVE-2023-50254CriDec 22, 2023
    risk 0.00cvss 9.3epss 0.02

    Deepin Linux's default document reader `deepin-reader` software suffers from a serious vulnerability in versions prior to 6.0.7 due to a design flaw that leads to remote command execution via crafted docx document. This is a file overwrite vulnerability. Remote code execution…

  • CVE-2023-27588HigMar 14, 2023
    risk 0.00cvss 7.5epss 0.01

    Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been discovered within Hasura GraphQL Engine prior to versions 1.3.4, 2.55.1, 2.20.1, and 2.21.0-beta1. Projects running on Hasura Cloud were not vulnerable. Self-hosted…