Skip to content
Noroxi

CWE-23 · 463 records

Relative Path Traversal

CVEs in this class

464 records

  • An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922.

    CriticalCVSS 9.8KEVWeaponizedEPSS 93%

    aviatrix · controllerSep 13, 2021

  • A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9

    CriticalCVSS 9.8KEVWeaponizedEPSS 92%

    fortinet · fortiwebNov 14, 2025

  • In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

    HighCVSS 7.3KEVWeaponizedEPSS 100%

    jetbrains · teamcityMar 4, 2024

  • Directory Traversal with spring-cloud-config-server

    HighCVSS 7.5KEVWeaponizedEPSS 96%

    vmware · spring cloud configJun 2, 2020

  • A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table

    MediumCVSS 6.7KEVWeaponizedEPSS 1%

    trendmicro · apex oneMay 21, 2026

  • Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftp

    CriticalCVSS 9.8No exploitEPSS 36%

    westerndigital · my cloud pr2100 firmwareJan 26, 2023

  • Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled

    HighCVSS 7.5Proof of conceptEPSS 64%

    apache · tomcatOct 27, 2025

  • Directory Traversal with spring-cloud-config-server

    MediumCVSS 6.5Proof of conceptEPSS 69%

    vmware · spring cloud configMar 5, 2020

  • A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized c

    CriticalCVSS 9.8Proof of conceptEPSS 25%

    fortinet · fortiwlmDec 18, 2024

  • Apache Flink directory traversal attack: remote file writing through the REST API

    HighCVSS 7.5Proof of conceptEPSS 51%

    apache · flinkJan 5, 2021

  • AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user

    HighCVSS 7.5Proof of conceptEPSS 46%

    aveva · intouch access anywhereDec 23, 2022

  • The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co

    CriticalCVSS 9.8No exploitEPSS 16%

    advantech · iviewJul 22, 2022

  • Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability

    HighCVSS 7.5Proof of conceptEPSS 45%

    articatech · artica proxyMar 20, 2024

  • XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash

    CriticalCVSS 9.3No exploitEPSS 20%

    xwiki · xwiki-commonsMay 20, 2026

  • mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vul

    HighCVSS 7.8No exploitEPSS 38%

    myscada · mydesignerNov 19, 2021

  • Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip

    HighCVSS 8.8WeaponizedEPSS 24%

    sitecore · experience commerceJun 17, 2025

  • Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

    CriticalCVSS 9.8No exploitEPSS 11%

    citrix · sd-wanNov 15, 2020

  • RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload

    CriticalCVSS 9.8WeaponizedEPSS 9%

    raspberrymatic · raspberrymaticMar 18, 2024

  • Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal

    CriticalCVSS 9.8No exploitEPSS 6%

    schneider-electric · easergy t300 firmwareMar 18, 2022

  • File Manager And File Manager Pro (Multiple Versions) - Directory Traversal

    CriticalCVSS 9.9Proof of conceptEPSS 6%

    mndpsingh287 · file managerMar 13, 2024

  • WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 5%

    themewinter · eventinMay 14, 2025

  • 3S CoDeSys Relative Path Traversal

    CriticalCVSS 10.0No exploitEPSS 3%

    3s-software · codesys runtime systemJan 21, 2013

  • An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.

    CriticalCVSS 9.1No exploitEPSS 14%

    advantech · webaccess\/nmsApr 9, 2020

  • Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.

    CriticalCVSS 9.8No exploitEPSS 4%

    advantech · webaccessMay 8, 2020

  • The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-ba

    CriticalCVSS 9.8No exploitEPSS 3%

    civetweb project · civetwebOct 21, 2021

All vulnerability classes