VYPR

CWE-35

Path Traversal: '.../...//'

VariantIncomplete

Description

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '.../...//' (doubled triple dot slash) sequences that can resolve to a location that is outside of that directory.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (180)

page 9 of 9
  • CVE-2025-26351MedFeb 12, 2025
    risk 0.32cvss 4.9epss 0.01

    A CWE-35 "Path Traversal" in the template download mechanism in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated remote attacker to read sensitive files via crafted HTTP requests.

  • CVE-2024-52390MedNov 18, 2024
    risk 0.32cvss 4.9epss 0.01

    Path Traversal: '.../...//' vulnerability in Greg Ross CYAN Backup cyan-backup allows Path Traversal.This issue affects CYAN Backup: from n/a through <= 2.5.3.

  • CVE-2026-1763MedFeb 10, 2026
    risk 0.30cvss 4.6epss 0.00

    Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.

  • CVE-2026-28265MedApr 1, 2026
    risk 0.29cvss 4.4epss 0.00

    PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.

  • CVE-2025-43886MedSep 10, 2025
    risk 0.29cvss 4.4epss 0.00

    Dell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) a Path Traversal: '.../...//' vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

  • CVE-2025-40573MedMay 13, 2025
    risk 0.29cvss 4.4epss 0.00

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0 HF0). Affected devices are vulnerable to path traversal attacks. This could allow a privileged local attacker to restore backups that are outside the backup folder.

  • CVE-2025-4956MedAug 30, 2025
    risk 0.28cvss 4.3epss 0.00

    Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through 2.0.

  • CVE-2024-47171MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.01

    Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload image files at attacker-chosen location on the server. This issue can lead to image file uploads to unauthorized or…

  • CVE-2024-47170MedSep 26, 2024
    risk 0.28cvss 4.3epss 0.00

    Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to read arbitrary JSON files at attacker-chosen locations on the server. This issue can lead to unauthorized access to…

  • CVE-2024-0067MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.00

    Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS versions for the…

  • CVE-2026-24315MedJun 9, 2026
    risk 0.27cvss 4.2epss 0.00

    SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by stealing user credentials. Successful exploitation requires adversaries to possess advanced knowledge…

  • CVE-2025-22288MedNov 6, 2025
    risk 0.27cvss 4.1epss 0.00

    Path Traversal: '.../...//' vulnerability in WPMU DEV - Your All-in-One WordPress Platform Smush Image Compression and Optimization wp-smushit allows Path Traversal.This issue affects Smush Image Compression and Optimization: from n/a through <= 3.17.0.

  • CVE-2025-52712MedAug 14, 2025
    risk 0.27cvss 4.2epss 0.00

    Path Traversal: '.../...//' vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Path Traversal.This issue affects Post and Page Builder by BoldGrid: from n/a through <= 1.27.8.

  • CVE-2024-1886LowFeb 26, 2024
    risk 0.20cvss 3.0epss 0.01

    This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

  • CVE-2025-58381LowFeb 3, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using the shell commands “source, ping6, sleep, disown, wait to modify the path variables and move upwards in the directory structure or to traverse to different…

  • CVE-2025-58380LowFeb 3, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.

  • CVE-2025-59181MedJul 27, 2026
    risk 0.00cvss epss 0.00

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.

  • CVE-2026-49779MedJul 2, 2026
    risk 0.00cvss 6.5epss 0.00

    Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.

  • CVE-2026-52707HigJun 17, 2026
    risk 0.00cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

  • CVE-2022-24774HigMar 22, 2022
    risk 0.00cvss 7.1epss 0.01

    CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit…