CWE-41 · 33 records
Improper Resolution of Path Equivalence
CVEs in this class
33 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2026-85978No exploit | Unauthenticated Remote Code Execution in Akana API Platformperforce · akana · CWE-41 | Critical10.0 | — | 1.4% | Sep 9, 2026 |
35Monitor | CVE-2025-21332No exploit | MapUrlToZone Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-41 | High8.8 | — | 1.5% | Jan 14, 2025 |
34Monitor | CVE-2025-24470No exploit | An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0fortinet · fortiportal · CWE-41 | High8.6 | — | 1.3% | Feb 11, 2025 |
33Monitor | CVE-2026-57441No exploit | MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalencebitbonsai · mcpvault · CWE-41 | High8.4 | — | 0.2% | Sep 15, 2026 |
33Monitor | CVE-2026-49401No exploit | Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)deno · deno · CWE-41 | High8.4 | — | 0.2% | Jun 23, 2026 |
32Monitor | CVE-2023-36396No exploit | Windows Compressed Folder Remote Code Execution Vulnerabilitymicrosoft · windows 11 22h2 · CWE-41 | High7.8 | — | 1.7% | Nov 14, 2023 |
32Monitor | CVE-2026-5816No exploit | Improper Resolution of Path Equivalence in GitLabgitlab · gitlab · CWE-41 | High8.1 | — | 0.6% | Apr 22, 2026 |
31Monitor | CVE-2024-30073No exploit | Windows Security Zone Mapping Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-41 | High7.8 | — | 0.9% | Sep 10, 2024 |
31Monitor | CVE-2025-43298No exploit | A parsing issue in the handling of directory paths was addressed with improved path validation.apple · macos · CWE-41 | High7.8 | — | 0.2% | Sep 15, 2025 |
30Monitor | CVE-2026-23674No exploit | MapUrlToZone Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-41 | High7.5 | — | 1.2% | Mar 10, 2026 |
30Monitor | CVE-2026-72835No exploit | filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalizationfilebrowser · filebrowser · CWE-41 | High7.6 | — | 0.5% | Aug 14, 2026 |
29Monitor | CVE-2024-8765No exploit | Improper Path Equivalence Resolution in lunary-ai/lunarylunary · lunary · CWE-41 | High7.3 | — | 0.8% | Mar 20, 2025 |
27Monitor | CVE-2024-30036No exploit | Windows Deployment Services Information Disclosure Vulnerabilitymicrosoft · windows server 2008 · CWE-41 | Medium6.5 | — | 2.3% | May 14, 2024 |
27Monitor | CVE-2026-34510No exploit | OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loadersopenclaw · openclaw · CWE-41 | Medium6.9 | — | 0.5% | Apr 1, 2026 |
27Monitor | CVE-2025-0115No exploit | PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLIpalo alto networks · pan-os · CWE-41 | Medium6.8 | — | 0.2% | Mar 12, 2025 |
26Monitor | CVE-2023-46169No exploit | IBM DS8900F file manipulationibm · ds8900f firmware · CWE-41 | Medium6.5 | — | 0.5% | Mar 7, 2024 |
24Monitor | CVE-2022-0855No exploit | Improper Resolution of Path Equivalence in microweber-dev/whmcs_pluginmicroweber · whmcs · CWE-41 | Medium6.1 | — | 1.0% | Mar 4, 2022 |
24Monitor | CVE-2024-45405No exploit | gix-path improperly resolves configuration path reported by Gitbyron · gitoxide · CWE-41 | Medium6.0 | — | 0.3% | Sep 6, 2024 |
22Monitor | CVE-2025-58290No exploit | Denial of service (DoS) vulnerability in the office service.huawei · harmonyos · CWE-41 | Medium5.5 | — | 0.1% | Oct 11, 2025 |
21Monitor | CVE-2023-45284No exploit | Incorrect detection of reserved device names on Windows in path/filepathgolang · go · CWE-41 | Medium5.3 | — | 0.9% | Nov 9, 2023 |
21Monitor | CVE-2024-6839No exploit | Improper Regex Path Matching in corydolphin/flask-corsflask-cors project · flask-cors · CWE-41 | Medium5.3 | — | 0.7% | Mar 20, 2025 |
21Monitor | CVE-2026-66064No exploit | goshs has ACL Bypass & Path Traversalgoshs-labs · goshs · CWE-41 | Medium5.3 | — | 0.4% | Jul 28, 2026 |
21Monitor | CVE-2026-93709No exploit | Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handlerCWE-41 | Medium5.3 | — | 0.3% | Sep 21, 2026 |
18Monitor | CVE-2025-21269No exploit | Windows HTML Platforms Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-41 | Medium4.3 | — | 4.6% | Jan 14, 2025 |
18Monitor | CVE-2025-21219No exploit | MapUrlToZone Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-41 | Medium4.3 | — | 3.0% | Jan 14, 2025 |
- CVE-2026-8597840Plan
Unauthenticated Remote Code Execution in Akana API Platform
CriticalCVSS 10.0No exploitEPSS 1%perforce · akanaSep 9, 2026
- CVE-2025-2133235Monitor
MapUrlToZone Security Feature Bypass Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · windows 10 1507Jan 14, 2025
- CVE-2025-2447034Monitor
An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0
HighCVSS 8.6No exploitEPSS 1%fortinet · fortiportalFeb 11, 2025
- CVE-2026-5744133Monitor
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
HighCVSS 8.4No exploitEPSS 0%bitbonsai · mcpvaultSep 15, 2026
- CVE-2026-4940133Monitor
Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
HighCVSS 8.4No exploitEPSS 0%deno · denoJun 23, 2026
- CVE-2023-3639632Monitor
Windows Compressed Folder Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 2%microsoft · windows 11 22h2Nov 14, 2023
- CVE-2026-581632Monitor
Improper Resolution of Path Equivalence in GitLab
HighCVSS 8.1No exploitEPSS 1%gitlab · gitlabApr 22, 2026
- CVE-2024-3007331Monitor
Windows Security Zone Mapping Security Feature Bypass Vulnerability
HighCVSS 7.8No exploitEPSS 1%microsoft · windows 10 1507Sep 10, 2024
- CVE-2025-4329831Monitor
A parsing issue in the handling of directory paths was addressed with improved path validation.
HighCVSS 7.8No exploitEPSS 0%apple · macosSep 15, 2025
- CVE-2026-2367430Monitor
MapUrlToZone Security Feature Bypass Vulnerability
HighCVSS 7.5No exploitEPSS 1%microsoft · windows 10 1607Mar 10, 2026
- CVE-2026-7283530Monitor
filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization
HighCVSS 7.6No exploitEPSS 1%filebrowser · filebrowserAug 14, 2026
- CVE-2024-876529Monitor
Improper Path Equivalence Resolution in lunary-ai/lunary
HighCVSS 7.3No exploitEPSS 1%lunary · lunaryMar 20, 2025
- CVE-2024-3003627Monitor
Windows Deployment Services Information Disclosure Vulnerability
MediumCVSS 6.5No exploitEPSS 2%microsoft · windows server 2008May 14, 2024
- CVE-2026-3451027Monitor
OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders
MediumCVSS 6.9No exploitEPSS 0%openclaw · openclawApr 1, 2026
- CVE-2025-011527Monitor
PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI
MediumCVSS 6.8No exploitEPSS 0%palo alto networks · pan-osMar 12, 2025
- CVE-2023-4616926Monitor
IBM DS8900F file manipulation
MediumCVSS 6.5No exploitEPSS 1%ibm · ds8900f firmwareMar 7, 2024
- CVE-2022-085524Monitor
Improper Resolution of Path Equivalence in microweber-dev/whmcs_plugin
MediumCVSS 6.1No exploitEPSS 1%microweber · whmcsMar 4, 2022
- CVE-2024-4540524Monitor
gix-path improperly resolves configuration path reported by Git
MediumCVSS 6.0No exploitEPSS 0%byron · gitoxideSep 6, 2024
- CVE-2025-5829022Monitor
Denial of service (DoS) vulnerability in the office service.
MediumCVSS 5.5No exploitEPSS 0%huawei · harmonyosOct 11, 2025
- CVE-2023-4528421Monitor
Incorrect detection of reserved device names on Windows in path/filepath
MediumCVSS 5.3No exploitEPSS 1%golang · goNov 9, 2023
- CVE-2024-683921Monitor
Improper Regex Path Matching in corydolphin/flask-cors
MediumCVSS 5.3No exploitEPSS 1%flask-cors project · flask-corsMar 20, 2025
- CVE-2026-6606421Monitor
goshs has ACL Bypass & Path Traversal
MediumCVSS 5.3No exploitEPSS 0%goshs-labs · goshsJul 28, 2026
- CVE-2026-9370921Monitor
Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler
MediumCVSS 5.3No exploitEPSS 0%Sep 21, 2026
- CVE-2025-2126918Monitor
Windows HTML Platforms Security Feature Bypass Vulnerability
MediumCVSS 4.3No exploitEPSS 5%microsoft · windows 10 1507Jan 14, 2025
- CVE-2025-2121918Monitor
MapUrlToZone Security Feature Bypass Vulnerability
MediumCVSS 4.3No exploitEPSS 3%microsoft · windows 10 1507Jan 14, 2025