VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (188)

page 10 of 10
  • CVE-2026-56089LowAug 17, 2026
    risk 0.21cvss 3.3epss 0.00

    Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

  • CVE-2024-1886LowFeb 26, 2024
    risk 0.20cvss 3.0epss 0.01

    This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

  • CVE-2025-58381LowFeb 3, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different…

  • CVE-2025-58380LowFeb 3, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.

  • CVE-2025-59181MedJul 27, 2026
    risk 0.00cvss —epss 0.00

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

  • CVE-2026-49779MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.

  • CVE-2026-52707HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

  • CVE-2022-24774HigMar 22, 2022
    risk 0.00cvss 7.1epss 0.01

    CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit…