CWE-36
Absolute Path Traversal
Description
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-597
CVEs mapped to this weakness (146)
page 7 of 8| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-53079 | Med | 0.32 | 4.9 | 0.00 | Jul 29, 2025 | Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files | ||
| CVE-2024-10651 | Med | 0.32 | 4.9 | 0.01 | Nov 1, 2024 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system files. | ||
| CVE-2026-20834 | Med | 0.30 | 4.6 | 0.01 | Jan 13, 2026 | Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | ||
| CVE-2026-32175 | Med | 0.28 | 4.3 | 0.01 | May 12, 2026 | A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited… | ||
| CVE-2025-15237 | Med | 0.28 | 4.3 | 0.00 | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability. | ||
| CVE-2025-15236 | Med | 0.28 | 4.3 | 0.00 | Jan 5, 2026 | QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability. | ||
| CVE-2025-14848 | Med | 0.28 | 4.3 | 0.01 | Dec 18, 2025 | Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files. | ||
| CVE-2023-4172 | Med | 0.28 | 4.3 | 0.01 | Aug 5, 2023 | A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to… | ||
| CVE-2023-2765 | Med | 0.28 | 4.3 | 0.02 | May 17, 2023 | A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated… | ||
| CVE-2023-2101 | Med | 0.28 | 4.3 | 0.01 | Apr 15, 2023 | A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal.… | ||
| CVE-2026-44029 | Med | 0.27 | 5.3 | 0.01 | May 5, 2026 | An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7); | ||
| CVE-2024-57966 | Med | 0.26 | 5.0 | 0.00 | Feb 3, 2025 | libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive. | ||
| CVE-2025-8009 | Med | 0.25 | 4.9 | 0.01 | Jul 24, 2025 | The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level… | ||
| CVE-2025-70820 | Low | 0.23 | 3.5 | 0.00 | Sep 13, 2026 | Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | ||
| CVE-2024-1703 | Low | 0.23 | 3.5 | 0.01 | Feb 21, 2024 | A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit has been disclosed to the public and may… | ||
| CVE-2025-67898 | Med | 0.22 | 4.5 | 0.00 | Dec 14, 2025 | MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827. | ||
| CVE-2023-50955 | Low | 0.16 | 2.4 | 0.01 | Feb 21, 2024 | IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777. | ||
| CVE-2023-1176 | Low | 0.14 | 3.3 | 0.01 | Mar 24, 2023 | Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2. | ||
| CVE-2026-15302 | Med | 0.00 | 5.3 | 0.01 | Jul 10, 2026 | The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the… | ||
| CVE-2026-58300 | Med | 0.00 | 6.2 | 0.00 | Jul 3, 2026 | Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. |
- risk 0.32cvss 4.9epss 0.00
Absolute Path Traversal in Samsung DMS(Data Management Server) allows authenticated attacker (Administrator) to read sensitive files
- risk 0.32cvss 4.9epss 0.01
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system files.
- risk 0.30cvss 4.6epss 0.01
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
- risk 0.28cvss 4.3epss 0.01
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker would have limited…
- risk 0.28cvss 4.3epss 0.00
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.
- risk 0.28cvss 4.3epss 0.00
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticated remote attackers to read folder names under the specified path by exploiting an Absolute Path Traversal vulnerability.
- risk 0.28cvss 4.3epss 0.01
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
- risk 0.28cvss 4.3epss 0.01
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of the argument FileDirectory leads to…
- risk 0.28cvss 4.3epss 0.02
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated…
- risk 0.28cvss 4.3epss 0.01
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument urlList leads to absolute path traversal.…
- risk 0.27cvss 5.3epss 0.01
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.34.7, 2.33.6, 2.32.8, 2.31.5, 2.30.5, 2.29.4, and 2.28.7 (introduced in 2.24.7);
- risk 0.26cvss 5.0epss 0.00
libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
- risk 0.25cvss 4.9epss 0.01
The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level…
- risk 0.23cvss 3.5epss 0.00
Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
- risk 0.23cvss 3.5epss 0.01
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit has been disclosed to the public and may…
- risk 0.22cvss 4.5epss 0.00
MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.
- risk 0.16cvss 2.4epss 0.01
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.
- risk 0.14cvss 3.3epss 0.01
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
- risk 0.00cvss 5.3epss 0.01
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via the 'X-FILENAME' HTTP header. This makes it possible for unauthenticated attackers to upload and overwrite certain files (e.g., CSS) to directories outside the…
- risk 0.00cvss 6.2epss 0.00
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.