CWE-35
Path Traversal: '.../...//'
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Parents
Children
none
CVEs mapped to this weakness (180)
page 5 of 9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-6252 | Hig | 0.49 | 7.5 | 0.01 | Nov 22, 2023 | Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read files located on the server and gain access to sensitive information such as configuration files. | ||
| CVE-2022-48476 | Hig | 0.49 | 7.5 | 0.01 | Apr 24, 2023 | In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible | ||
| CVE-2022-3693 | Hig | 0.49 | 7.5 | 0.01 | Jan 13, 2023 | Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Management System: from unspecified before 10.6.3. | ||
| CVE-2022-2265 | Hig | 0.49 | 7.5 | 0.01 | Sep 21, 2022 | The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25 | ||
| CVE-2026-25705 | Hig | 0.48 | 8.4 | 0.00 | May 13, 2026 | A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin`… | ||
| CVE-2025-64676 | Hig | 0.47 | 7.2 | 0.01 | Dec 18, 2025 | '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. | ||
| CVE-2025-58972 | Hig | 0.47 | 7.2 | 0.00 | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager:… | ||
| CVE-2025-26356 | Hig | 0.47 | 7.2 | 0.01 | Feb 12, 2025 | A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests. | ||
| CVE-2025-26354 | Hig | 0.47 | 7.2 | 0.01 | Feb 12, 2025 | A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests. | ||
| CVE-2023-7263 | Hig | 0.47 | 7.3 | 0.00 | Dec 28, 2024 | Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability ID:HWPSIRT-2023-53450) This vulnerability has been assigned a… | ||
| CVE-2024-27901 | Hig | 0.47 | 7.2 | 0.01 | Apr 9, 2024 | SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application. | ||
| CVE-2023-21418 | Hig | 0.46 | 7.1 | 0.01 | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service… | ||
| CVE-2023-21417 | Hig | 0.46 | 7.1 | 0.01 | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator-… | ||
| CVE-2023-21416 | Hig | 0.46 | 7.1 | 0.01 | Nov 21, 2023 | Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can… | ||
| CVE-2025-60835 | Hig | 0.44 | 7.8 | 0.00 | Jul 22, 2026 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. | ||
| CVE-2026-24464 | — | Med | 0.44 | 6.8 | 0.01 | May 13, 2026 | When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have… | |
| CVE-2026-0804 | Med | 0.44 | 6.7 | 0.00 | May 12, 2026 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,… | ||
| CVE-2026-42274 | Hig | 0.44 | — | 0.00 | May 8, 2026 | Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3.… | ||
| CVE-2026-0205 | Med | 0.44 | 6.8 | 0.00 | Apr 29, 2026 | A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. | ||
| CVE-2026-26124 | Med | 0.44 | 6.7 | 0.00 | Mar 5, 2026 | '.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. |
- risk 0.49cvss 7.5epss 0.01
Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read files located on the server and gain access to sensitive information such as configuration files.
- risk 0.49cvss 7.5epss 0.01
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
- risk 0.49cvss 7.5epss 0.01
Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue affects FileOrbis File Management System: from unspecified before 10.6.3.
- risk 0.49cvss 7.5epss 0.01
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before version 2.1.25 has an unauthenticated Path traversal vulnerability. This has been fixed in the version 2.1.25
- risk 0.48cvss 8.4epss 0.00
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin`…
- risk 0.47cvss 7.2epss 0.01
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
- risk 0.47cvss 7.2epss 0.00
Path Traversal: '.../...//' vulnerability in Dmitry V. (CEO of "UKR Solution") Barcode Scanner with Inventory & Order Manager barcode-scanner-lite-pos-to-manage-products-inventory-and-orders allows Path Traversal.This issue affects Barcode Scanner with Inventory & Order Manager:…
- risk 0.47cvss 7.2epss 0.01
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.
- risk 0.47cvss 7.2epss 0.01
A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to overwrite sensitive files via crafted HTTP requests.
- risk 0.47cvss 7.3epss 0.00
Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability ID:HWPSIRT-2023-53450) This vulnerability has been assigned a…
- risk 0.47cvss 7.2epss 0.01
SAP Asset Accounting could allow a high privileged attacker to exploit insufficient validation of path information provided by the users and pass it through to the file API's. Thus, causing a considerable impact on confidentiality, integrity and availability of the application.
- risk 0.46cvss 7.1epss 0.01
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to path traversal attacks that allows for file deletion. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service…
- risk 0.46cvss 7.1epss 0.01
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnerable to path traversal attacks that allows for file/folder deletion. This flaw can only be exploited after authenticating with an operator- or administrator-…
- risk 0.46cvss 7.1epss 0.01
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API dynamicoverlay.cgi was vulnerable to a Denial-of-Service attack allowing for an attacker to block access to the overlay configuration page in the web interface of the Axis device. This flaw can…
- risk 0.44cvss 7.8epss 0.00
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
- risk 0.44cvss 6.8epss 0.01
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have…
- risk 0.44cvss 6.7epss 0.00
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications,…
- risk 0.44cvss —epss 0.00
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstream components may normalize dot-segments according to RFC 3986, Section 6.2.2.3.…
- risk 0.44cvss 6.8epss 0.00
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
- risk 0.44cvss 6.7epss 0.00
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.