← Back
CWE-23

490 CVEs • Abstraction: Base

Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

JSON object

Loading...

CVEs (490)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lcds
1Laquis Scada
Nov 21, 2024
Feb 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of...Show more
LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process.Show less
1Opensuse
1Open Build Service
Nov 21, 2024
Oct 2, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker...Show more
A path traversal traversal vulnerability in obs-service-tar_scm of Open Build Service allows remote attackers to cause access files not in the current build. On the server itself this is prevented by confining the worker via KVM. Affected releases are openSUSE Open Build Service: versions prior to 70d1aa4cc4d7b940180553a63805c22fc62e2cf0.Show less
1Emerson
1Deltav
Nov 21, 2024
Aug 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.
1Ge
1Mds Pulsenet
Nov 21, 2024
Jun 4, 2018
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform.
1Abb
2Srea 01 Firmware
Srea 50 Firmware
Nov 21, 2024
May 24, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring to...Show more
In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to 3.32.8, an attacker may access internal files of ABB SREA-01 and SREA-50 legacy remote monitoring tools without any authorization over the network using a HTTP request which refers to files using ../../ relative paths. Once the internal password file is retrieved, the password hash can be identified using a brute force attack. There is also an exploit allowing running of commands after authorization.Show less
1Medtronic
12090 Carelink Programmer Firmware
Jun 17, 2026
May 4, 2018
N/A· v4
5.7 MEDIUM· v3
2.7 LOW· v2
Medtronic 2090 CareLink Programmer’s software deployment network contains a directory traversal vulnerability that could allow an attacker to read files on the system.
2Debian
Gitlab
2Debian Linux
Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Gitlab Community Edition version 10.3 is vulnerable to a path traversal issue in the GitLab CI runner component resulting in remote code execution.
1Loytec
1Lvis 3me Firmware
May 13, 2026
Oct 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which c...Show more
A Relative Path Traversal issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The web user interface fails to prevent access to critical files that non administrative users should not have access to, which could allow an attacker to create or modify files or execute arbitrary code.Show less
13s Software
1Codesys Runtime System
Apr 29, 2026
Jan 21, 2013
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload an...Show more
The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability, integrity, and confidentiality of the device.Show less
1Specview
1Specview
Apr 29, 2026
Jan 17, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.