Skip to content
Noroxi

CWE-41 · 33 records

Improper Resolution of Path Equivalence

CVEs in this class

33 records

  • Unauthenticated Remote Code Execution in Akana API Platform

    CriticalCVSS 10.0No exploitEPSS 1%

    perforce · akanaSep 9, 2026

  • MapUrlToZone Security Feature Bypass Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · windows 10 1507Jan 14, 2025

  • An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0

    HighCVSS 8.6No exploitEPSS 1%

    fortinet · fortiportalFeb 11, 2025

  • MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

    HighCVSS 8.4No exploitEPSS 0%

    bitbonsai · mcpvaultSep 15, 2026

  • Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

    HighCVSS 8.4No exploitEPSS 0%

    deno · denoJun 23, 2026

  • Windows Compressed Folder Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 2%

    microsoft · windows 11 22h2Nov 14, 2023

  • CVE-2026-5816
    32Monitor

    Improper Resolution of Path Equivalence in GitLab

    HighCVSS 8.1No exploitEPSS 1%

    gitlab · gitlabApr 22, 2026

  • Windows Security Zone Mapping Security Feature Bypass Vulnerability

    HighCVSS 7.8No exploitEPSS 1%

    microsoft · windows 10 1507Sep 10, 2024

  • A parsing issue in the handling of directory paths was addressed with improved path validation.

    HighCVSS 7.8No exploitEPSS 0%

    apple · macosSep 15, 2025

  • MapUrlToZone Security Feature Bypass Vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    microsoft · windows 10 1607Mar 10, 2026

  • filebrowser before v2.63.21 Access Rule Bypass via Path Canonicalization

    HighCVSS 7.6No exploitEPSS 1%

    filebrowser · filebrowserAug 14, 2026

  • CVE-2024-8765
    29Monitor

    Improper Path Equivalence Resolution in lunary-ai/lunary

    HighCVSS 7.3No exploitEPSS 1%

    lunary · lunaryMar 20, 2025

  • Windows Deployment Services Information Disclosure Vulnerability

    MediumCVSS 6.5No exploitEPSS 2%

    microsoft · windows server 2008May 14, 2024

  • OpenClaw < 2026.3.22 - Remote File URL Acceptance in Windows Media Loaders

    MediumCVSS 6.9No exploitEPSS 0%

    openclaw · openclawApr 1, 2026

  • CVE-2025-0115
    27Monitor

    PAN-OS: Authenticated Admin File Read Vulnerability in PAN-OS CLI

    MediumCVSS 6.8No exploitEPSS 0%

    palo alto networks · pan-osMar 12, 2025

  • IBM DS8900F file manipulation

    MediumCVSS 6.5No exploitEPSS 1%

    ibm · ds8900f firmwareMar 7, 2024

  • CVE-2022-0855
    24Monitor

    Improper Resolution of Path Equivalence in microweber-dev/whmcs_plugin

    MediumCVSS 6.1No exploitEPSS 1%

    microweber · whmcsMar 4, 2022

  • gix-path improperly resolves configuration path reported by Git

    MediumCVSS 6.0No exploitEPSS 0%

    byron · gitoxideSep 6, 2024

  • Denial of service (DoS) vulnerability in the office service.

    MediumCVSS 5.5No exploitEPSS 0%

    huawei · harmonyosOct 11, 2025

  • Incorrect detection of reserved device names on Windows in path/filepath

    MediumCVSS 5.3No exploitEPSS 1%

    golang · goNov 9, 2023

  • CVE-2024-6839
    21Monitor

    Improper Regex Path Matching in corydolphin/flask-cors

    MediumCVSS 5.3No exploitEPSS 1%

    flask-cors project · flask-corsMar 20, 2025

  • goshs has ACL Bypass & Path Traversal

    MediumCVSS 5.3No exploitEPSS 0%

    goshs-labs · goshsJul 28, 2026

  • Dancer2 versions before 2.2.0 for Perl serve a layout as a page when an equivalent spelling of its path misses the guard in the AutoPage handler

    MediumCVSS 5.3No exploitEPSS 0%

    Sep 21, 2026

  • Windows HTML Platforms Security Feature Bypass Vulnerability

    MediumCVSS 4.3No exploitEPSS 5%

    microsoft · windows 10 1507Jan 14, 2025

  • MapUrlToZone Security Feature Bypass Vulnerability

    MediumCVSS 4.3No exploitEPSS 3%

    microsoft · windows 10 1507Jan 14, 2025

All vulnerability classes