CWE-23 · 463 records
Relative Path Traversal
CVEs in this class
464 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
97Now | CVE-2021-40870Weaponized | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922.aviatrix · controller · CWE-23 | Critical9.8 | KEV | 93.0% | Sep 13, 2021 |
97Now | CVE-2025-64446Weaponized | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9fortinet · fortiweb · CWE-23 | Critical9.8 | KEV | 91.8% | Nov 14, 2025 |
89Now | CVE-2024-27199Weaponized | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possiblejetbrains · teamcity · CWE-23 | High7.3 | KEV | 100.0% | Mar 4, 2024 |
89Now | CVE-2020-5410Weaponized | Directory Traversal with spring-cloud-config-servervmware · spring cloud config · CWE-23 | High7.5 | KEV | 95.6% | Jun 2, 2020 |
56Plan | CVE-2026-34926Weaponized | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key tabletrendmicro · apex one · CWE-23 | Medium6.7 | KEV | 0.5% | May 21, 2026 |
50Plan | CVE-2022-29844No exploit | Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftpwesterndigital · my cloud pr2100 firmware · CWE-23 | Critical9.8 | — | 36.4% | Jan 26, 2023 |
49Plan | CVE-2025-55752Proof of concept | Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabledapache · tomcat · CWE-23 | High7.5 | — | 64.4% | Oct 27, 2025 |
47Plan | CVE-2020-5405Proof of concept | Directory Traversal with spring-cloud-config-servervmware · spring cloud config · CWE-23 | Medium6.5 | — | 68.8% | Mar 5, 2020 |
46Plan | CVE-2023-34990Proof of concept | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized cfortinet · fortiwlm · CWE-23 | Critical9.8 | — | 24.8% | Dec 18, 2024 |
45Plan | CVE-2020-17518Proof of concept | Apache Flink directory traversal attack: remote file writing through the REST APIapache · flink · CWE-23 | High7.5 | — | 51.4% | Jan 5, 2021 |
44Plan | CVE-2022-23854Proof of concept | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated useraveva · intouch access anywhere · CWE-23 | High7.5 | — | 46.0% | Dec 23, 2022 |
44Plan | CVE-2022-2139No exploit | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary coadvantech · iview · CWE-23 | Critical9.8 | — | 15.6% | Jul 22, 2022 |
43Plan | CVE-2024-2053Proof of concept | Artica Proxy Unauthenticated LFI Protection Bypass Vulnerabilityarticatech · artica proxy · CWE-23 | High7.5 | — | 44.6% | Mar 20, 2024 |
43Plan | CVE-2026-23734No exploit | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slashxwiki · xwiki-commons · CWE-23 | Critical9.3 | — | 19.6% | May 20, 2026 |
42Plan | CVE-2021-43555No exploit | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulmyscada · mydesigner · CWE-23 | High7.8 | — | 38.2% | Nov 19, 2021 |
42Plan | CVE-2025-34510Weaponized | Sitecore XM, XC, and XP Post-Auth RCE via Zip Slipsitecore · experience commerce · CWE-23 | High8.8 | — | 24.3% | Jun 17, 2025 |
42Plan | CVE-2020-8271No exploit | Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8citrix · sd-wan · CWE-23 | Critical9.8 | — | 11.1% | Nov 15, 2020 |
42Plan | CVE-2024-24578Weaponized | RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Uploadraspberrymatic · raspberrymatic · CWE-23 | Critical9.8 | — | 8.7% | Mar 18, 2024 |
41Plan | CVE-2020-25176No exploit | Rockwell Automation ISaGRAF5 Runtime Relative Path Traversalschneider-electric · easergy t300 firmware · CWE-23 | Critical9.8 | — | 6.4% | Mar 18, 2022 |
41Plan | CVE-2023-6825Proof of concept | File Manager And File Manager Pro (Multiple Versions) - Directory Traversalmndpsingh287 · file manager · CWE-23 | Critical9.9 | — | 6.0% | Mar 13, 2024 |
41Plan | CVE-2025-47445Proof of concept | WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerabilitythemewinter · eventin · CWE-23 | Critical9.8 | — | 5.1% | May 14, 2025 |
41Plan | CVE-2012-6069No exploit | 3S CoDeSys Relative Path Traversal3s-software · codesys runtime system · CWE-23 | Critical10.0 | — | 2.6% | Jan 21, 2013 |
40Plan | CVE-2020-10619No exploit | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.advantech · webaccess\/nms · CWE-23 | Critical9.1 | — | 14.3% | Apr 9, 2020 |
40Plan | CVE-2020-12006No exploit | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-23 | Critical9.8 | — | 3.7% | May 8, 2020 |
40Plan | CVE-2020-27304No exploit | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-bacivetweb project · civetweb · CWE-23 | Critical9.8 | — | 3.2% | Oct 21, 2021 |
- CVE-2021-4087097Now
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922.
CriticalCVSS 9.8KEVWeaponizedEPSS 93%aviatrix · controllerSep 13, 2021
- CVE-2025-6444697Now
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9
CriticalCVSS 9.8KEVWeaponizedEPSS 92%fortinet · fortiwebNov 14, 2025
- CVE-2024-2719989Now
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
HighCVSS 7.3KEVWeaponizedEPSS 100%jetbrains · teamcityMar 4, 2024
- CVE-2020-541089Now
Directory Traversal with spring-cloud-config-server
HighCVSS 7.5KEVWeaponizedEPSS 96%vmware · spring cloud configJun 2, 2020
- CVE-2026-3492656Plan
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table
MediumCVSS 6.7KEVWeaponizedEPSS 1%trendmicro · apex oneMay 21, 2026
- CVE-2022-2984450Plan
Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftp
CriticalCVSS 9.8No exploitEPSS 36%westerndigital · my cloud pr2100 firmwareJan 26, 2023
- CVE-2025-5575249Plan
Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
HighCVSS 7.5Proof of conceptEPSS 64%apache · tomcatOct 27, 2025
- CVE-2020-540547Plan
Directory Traversal with spring-cloud-config-server
MediumCVSS 6.5Proof of conceptEPSS 69%vmware · spring cloud configMar 5, 2020
- CVE-2023-3499046Plan
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized c
CriticalCVSS 9.8Proof of conceptEPSS 25%fortinet · fortiwlmDec 18, 2024
- CVE-2020-1751845Plan
Apache Flink directory traversal attack: remote file writing through the REST API
HighCVSS 7.5Proof of conceptEPSS 51%apache · flinkJan 5, 2021
- CVE-2022-2385444Plan
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user
HighCVSS 7.5Proof of conceptEPSS 46%aveva · intouch access anywhereDec 23, 2022
- CVE-2022-213944Plan
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co
CriticalCVSS 9.8No exploitEPSS 16%advantech · iviewJul 22, 2022
- CVE-2024-205343Plan
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
HighCVSS 7.5Proof of conceptEPSS 45%articatech · artica proxyMar 20, 2024
- CVE-2026-2373443Plan
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
CriticalCVSS 9.3No exploitEPSS 20%xwiki · xwiki-commonsMay 20, 2026
- CVE-2021-4355542Plan
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vul
HighCVSS 7.8No exploitEPSS 38%myscada · mydesignerNov 19, 2021
- CVE-2025-3451042Plan
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
HighCVSS 8.8WeaponizedEPSS 24%sitecore · experience commerceJun 17, 2025
- CVE-2020-827142Plan
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
CriticalCVSS 9.8No exploitEPSS 11%citrix · sd-wanNov 15, 2020
- CVE-2024-2457842Plan
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
CriticalCVSS 9.8WeaponizedEPSS 9%raspberrymatic · raspberrymaticMar 18, 2024
- CVE-2020-2517641Plan
Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal
CriticalCVSS 9.8No exploitEPSS 6%schneider-electric · easergy t300 firmwareMar 18, 2022
- CVE-2023-682541Plan
File Manager And File Manager Pro (Multiple Versions) - Directory Traversal
CriticalCVSS 9.9Proof of conceptEPSS 6%mndpsingh287 · file managerMar 13, 2024
- CVE-2025-4744541Plan
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 5%themewinter · eventinMay 14, 2025
- CVE-2012-606941Plan
3S CoDeSys Relative Path Traversal
CriticalCVSS 10.0No exploitEPSS 3%3s-software · codesys runtime systemJan 21, 2013
- CVE-2020-1061940Plan
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
CriticalCVSS 9.1No exploitEPSS 14%advantech · webaccess\/nmsApr 9, 2020
- CVE-2020-1200640Plan
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
CriticalCVSS 9.8No exploitEPSS 4%advantech · webaccessMay 8, 2020
- CVE-2020-2730440Plan
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-ba
CriticalCVSS 9.8No exploitEPSS 3%civetweb project · civetwebOct 21, 2021