CWE-23
456 CVEs • Abstraction: Base
Relative Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CVEs (456)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting version 4.7.18. An unauthenticated attacker could extract sensitive information from the server via t...Show more |
Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucke...Show more |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreJun 17, 2026 Sep 10, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability |
1Microsoft 6Windows Server 2008 Windows Server 2012Windows Server 2016+3 moreJun 17, 2026 Sep 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Windows Remote Desktop Licensing Service Information Disclosure Vulnerability |
1Opensecurity 1Mobile Security Framework Jun 17, 2026 Aug 19, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. Before 4.0.7, there is a flaw in the Static Libraries analysis sec...Show more |
Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing unauthenticated remote attackers to read arbitrary file on the remote server. |
The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files on the system by providing a crafted path. This vulnerability can be exploited by sending a request...Show more |
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system. |
A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository, affecting the latest version. The vulnerability arises due to insufficient sanitization of the 'pro...Show more |
1Dell 1Data Domain Operating System Jun 17, 2026 Jun 26, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path traversal vulnerability. A remote high privileged attacker could potentially exploit this vulnerabili...Show more |
Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add new ones to the printer. As for the affected products/models/versions, see the reference URL. |
If exploited an attacker could traverse the file system to access
files or directories that would otherwise be inaccessible |
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulnerability arises due to improper handling of user-supplied input in the 'list_personalities'...Show more |
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files from server was possible |
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned, place new files any...Show more |
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system with root privileges. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR...Show more |
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system. This issue affects ZkTeco-based OEM devices (ZkTeco ProFace X, Smartec ST-FR043, Smartec ST-FR04...Show more |
A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel server, which allows file writing to the server outside the intended scope, and could allow an attacker...Show more |
1Microsoft 5Windows Server 2012 Windows Server 2016Windows Server 2019+2 moreJun 17, 2026 May 14, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows Hyper-V Remote Code Execution Vulnerability |
Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.rest.channels.removeBan` is not url-encoded, resulting in specially crafted input such as `../../../ch...Show more |