CWE-35
Path Traversal: '.../...//'
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (180)
page 1 of 9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-8088 | Hig | 0.83 | 8.8 | 0.95 | KEV | Aug 8, 2025 | A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček … | |
| CVE-2026-59115 | Cri | 0.64 | 9.9 | 0.01 | Aug 7, 2026 | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-6074 | Cri | 0.64 | 9.8 | 0.01 | Apr 23, 2026 | Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended… | ||
| CVE-2025-59793 | Cri | 0.64 | 9.9 | 0.01 | Feb 17, 2026 | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to… | ||
| CVE-2025-41723 | — | Cri | 0.64 | 9.8 | 0.01 | Oct 22, 2025 | The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations. | |
| CVE-2025-42937 | Cri | 0.64 | 9.8 | 0.01 | Oct 14, 2025 | SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the… | ||
| CVE-2025-30515 | Cri | 0.64 | 9.8 | 0.01 | Jun 9, 2025 | CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system. | ||
| CVE-2024-39171 | Cri | 0.64 | 9.8 | 0.01 | Jul 9, 2024 | Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix. | ||
| CVE-2020-27130 | Cri | 0.64 | 9.1 | 0.66 | Nov 17, 2020 | A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. An attacker could… | ||
| CVE-2018-3744 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL. | ||
| CVE-2026-52703 | Cri | 0.62 | 9.6 | 0.00 | Jun 15, 2026 | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | ||
| CVE-2025-53417 | Cri | 0.61 | — | 0.11 | Aug 5, 2025 | DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability | ||
| CVE-2024-56045 | Cri | 0.61 | 9.3 | 0.01 | Dec 31, 2024 | Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5. | ||
| CVE-2025-5598 | Cri | 0.60 | — | 0.00 | Jun 4, 2025 | Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046. | ||
| CVE-2024-40505 | Cri | 0.60 | 9.3 | 0.00 | Jul 16, 2024 | Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component. | ||
| CVE-2026-13716 | Cri | 0.59 | 9.1 | 0.01 | Aug 11, 2026 | Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution. | ||
| CVE-2026-40128 | Cri | 0.59 | 9.0 | 0.00 | Jun 9, 2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the… | ||
| CVE-2026-7302 | Cri | 0.59 | 9.1 | 0.00 | May 18, 2026 | SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints. | ||
| CVE-2025-24786 | Cri | 0.58 | 10.0 | 0.03 | Feb 6, 2025 | WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sqlite3 database present on the host… | ||
| CVE-2026-42661 | Hig | 0.57 | 8.8 | 0.00 | Jun 15, 2026 | Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. |
- risk 0.83cvss 8.8epss 0.95
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček …
- risk 0.64cvss 9.9epss 0.01
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.8epss 0.01
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthenticated attacker can manipulate the name parameter to read arbitrary files outside the intended…
- risk 0.64cvss 9.9epss 0.01
Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authenticated users to be able to upload files. However, the application doesn't properly sanitize the jobDirectory parameter, which allows path traversal sequences to…
- risk 0.64cvss 9.8epss 0.01
The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the path restriction and upload files to arbitrary locations.
- risk 0.64cvss 9.8epss 0.01
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality integrity and availability of the…
- risk 0.64cvss 9.8epss 0.01
CyberData 011209 Intercom could allow an authenticated attacker to upload arbitrary files to multiple locations within the system.
- risk 0.64cvss 9.8epss 0.01
Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.
- risk 0.64cvss 9.1epss 0.66
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversal character sequences within requests to an affected device. An attacker could…
- risk 0.64cvss 9.8epss 0.02
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
- risk 0.62cvss 9.6epss 0.00
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
- risk 0.61cvss —epss 0.11
DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
- risk 0.61cvss 9.3epss 0.01
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS wplms_plugin allows Path Traversal.This issue affects WPLMS: from n/a through < 1.9.9.5.
- risk 0.60cvss —epss 0.00
Path Traversal vulnerability in WF Steuerungstechnik GmbH airleader MASTER allows Retrieve Embedded Sensitive Data.This issue affects airleader MASTER: 3.0046.
- risk 0.60cvss 9.3epss 0.00
Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.
- risk 0.59cvss 9.1epss 0.01
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.
- risk 0.59cvss 9.0epss 0.00
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the…
- risk 0.59cvss 9.1epss 0.00
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by including ../ sequences in the upload filename when sent to specific endpoints.
- risk 0.58cvss 10.0epss 0.03
WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sqlite3 database present on the host…
- risk 0.57cvss 8.8epss 0.00
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.