CWE-24 · 103 records
Path Traversal: '../filedir'
CVEs in this class
103 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-2025-27920Weaponized | Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling.srimax · output messenger · CWE-24 | High8.8 | KEV | 1.9% | May 5, 2025 |
40Plan | CVE-2023-1800No exploit | sjqzhang go-fastdfs File Upload uploa upload path traversalgo-fastdfs project · go-fastdfs · CWE-24 | Critical9.8 | — | 3.6% | Apr 2, 2023 |
39Monitor | CVE-2024-53636No exploit | An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackeacademiaerp · student information system · CWE-24 | Critical9.8 | — | 1.6% | Apr 26, 2025 |
39Monitor | CVE-2023-3057No exploit | YFCMF Ajax.php path traversaliuok · yfcmf-tp6 · CWE-24 | Critical9.8 | — | 1.2% | Jun 2, 2023 |
39Monitor | CVE-2023-3056No exploit | YFCMF index.php path traversaliuok · yfcmf-tp6 · CWE-24 | Critical9.8 | — | 1.2% | Jun 2, 2023 |
39Monitor | CVE-2024-0989No exploit | Sichuan Yougou Technology KuERP Service.php del_sn_db path traversalkuerp project · kuerp · CWE-24 | Critical9.8 | — | 1.2% | Jan 28, 2024 |
39Monitor | CVE-2024-0417No exploit | DeShang DSShop MemberAuth.php path traversalcsdeshang · dsshop · CWE-24 | Critical9.8 | — | 1.1% | Jan 11, 2024 |
39Monitor | CVE-2024-0416No exploit | DeShang DSMall MemberAuth.php path traversalcsdeshang · dsmall · CWE-24 | Critical9.8 | — | 0.9% | Jan 11, 2024 |
39Monitor | CVE-2023-7134No exploit | SourceCodester Medicine Tracking System path traversaloretnom23 · medicine tracker system · CWE-24 | Critical9.8 | — | 0.9% | Dec 28, 2023 |
39Monitor | CVE-2025-43928No exploit | In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversalinfodraw · pmrs-102 firmware · CWE-24 | Critical9.8 | — | 0.9% | Apr 19, 2025 |
39Monitor | CVE-2024-2563No exploit | PandaXGO PandaX upload.go DeleteImage path traversalpandax · pandax · CWE-24 | Critical9.8 | — | 0.9% | Mar 17, 2024 |
39Monitor | CVE-2023-7058No exploit | SourceCodester Simple Student Attendance System path traversaloretnom23 · simple student attendance system · CWE-24 | Critical9.8 | — | 0.7% | Dec 22, 2023 |
39Monitor | CVE-2026-39813Proof of concept | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attackfortinet · fortisandbox · CWE-24 | Critical9.8 | — | 0.7% | Apr 14, 2026 |
37Monitor | CVE-2025-60344No exploit | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpud-link · dsr-150 · CWE-24 | High8.6 | — | 10.9% | Oct 21, 2025 |
37Monitor | CVE-2026-49103No exploit | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.webmin · webmin · CWE-24 | Critical9.4 | — | 0.5% | May 27, 2026 |
36Monitor | CVE-2021-33036No exploit | Apache Hadoop Privilege escalation vulnerabilityapache · hadoop · CWE-24 | High8.8 | — | 3.9% | Jun 15, 2022 |
36Monitor | CVE-2025-54769Proof of concept | KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversalxorux · lpar2rrd · CWE-24 | High8.8 | — | 3.3% | Jul 28, 2025 |
36Monitor | CVE-2020-7882Proof of concept | anySign directory traversal vulnerabilityhancom · anysign4pc · CWE-24 | Critical9.1 | — | 1.3% | Nov 22, 2021 |
36Monitor | CVE-2023-6900No exploit | rmountjoy92 DashMachine delete_file path traversalrmountjoy92 · dashmachine · CWE-24 | Critical9.1 | — | 1.1% | Dec 17, 2023 |
36Monitor | CVE-2025-61318No exploit | Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.emlog · emlog · CWE-24 | Critical9.1 | — | 0.7% | Dec 8, 2025 |
35Monitor | CVE-2023-1398No exploit | XiaoBingBy TeaCMS upload path traversalteacms project · teacms · CWE-24 | High8.8 | — | 1.0% | Mar 14, 2023 |
35Monitor | CVE-2024-2825No exploit | lakernote EasyAdmin saveReportFile path traversallakernote · easyadmin · CWE-24 | High8.8 | — | 0.7% | Mar 22, 2024 |
34Monitor | CVE-2026-14947No exploit | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP filefrauscher sensortechnik · fds 102 · CWE-24 | High8.6 | — | 1.5% | Aug 20, 2026 |
34Monitor | CVE-2021-26725No exploit | Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4nozominetworks · central management control · CWE-24 | High8.6 | — | 1.1% | Feb 22, 2021 |
34Monitor | CVE-2026-97730No exploit | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) winetgate · pfsense plus · CWE-24 | High8.5 | — | 1.0% | Sep 25, 2026 |
- CVE-2025-2792066This week
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling.
HighCVSS 8.8KEVWeaponizedEPSS 2%srimax · output messengerMay 5, 2025
- CVE-2023-180040Plan
sjqzhang go-fastdfs File Upload uploa upload path traversal
CriticalCVSS 9.8No exploitEPSS 4%go-fastdfs project · go-fastdfsApr 2, 2023
- CVE-2024-5363639Monitor
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attacke
CriticalCVSS 9.8No exploitEPSS 2%academiaerp · student information systemApr 26, 2025
- CVE-2023-305739Monitor
YFCMF Ajax.php path traversal
CriticalCVSS 9.8No exploitEPSS 1%iuok · yfcmf-tp6Jun 2, 2023
- CVE-2023-305639Monitor
YFCMF index.php path traversal
CriticalCVSS 9.8No exploitEPSS 1%iuok · yfcmf-tp6Jun 2, 2023
- CVE-2024-098939Monitor
Sichuan Yougou Technology KuERP Service.php del_sn_db path traversal
CriticalCVSS 9.8No exploitEPSS 1%kuerp project · kuerpJan 28, 2024
- CVE-2024-041739Monitor
DeShang DSShop MemberAuth.php path traversal
CriticalCVSS 9.8No exploitEPSS 1%csdeshang · dsshopJan 11, 2024
- CVE-2024-041639Monitor
DeShang DSMall MemberAuth.php path traversal
CriticalCVSS 9.8No exploitEPSS 1%csdeshang · dsmallJan 11, 2024
- CVE-2023-713439Monitor
SourceCodester Medicine Tracking System path traversal
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · medicine tracker systemDec 28, 2023
- CVE-2025-4392839Monitor
In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal
CriticalCVSS 9.8No exploitEPSS 1%infodraw · pmrs-102 firmwareApr 19, 2025
- CVE-2024-256339Monitor
PandaXGO PandaX upload.go DeleteImage path traversal
CriticalCVSS 9.8No exploitEPSS 1%pandax · pandaxMar 17, 2024
- CVE-2023-705839Monitor
SourceCodester Simple Student Attendance System path traversal
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · simple student attendance systemDec 22, 2023
- CVE-2026-3981339Monitor
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attack
CriticalCVSS 9.8Proof of conceptEPSS 1%fortinet · fortisandboxApr 14, 2026
- CVE-2025-6034437Monitor
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpu
HighCVSS 8.6No exploitEPSS 11%d-link · dsr-150Oct 21, 2025
- CVE-2026-4910337Monitor
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.
CriticalCVSS 9.4No exploitEPSS 0%webmin · webminMay 27, 2026
- CVE-2021-3303636Monitor
Apache Hadoop Privilege escalation vulnerability
HighCVSS 8.8No exploitEPSS 4%apache · hadoopJun 15, 2022
- CVE-2025-5476936Monitor
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
HighCVSS 8.8Proof of conceptEPSS 3%xorux · lpar2rrdJul 28, 2025
- CVE-2020-788236Monitor
anySign directory traversal vulnerability
CriticalCVSS 9.1Proof of conceptEPSS 1%hancom · anysign4pcNov 22, 2021
- CVE-2023-690036Monitor
rmountjoy92 DashMachine delete_file path traversal
CriticalCVSS 9.1No exploitEPSS 1%rmountjoy92 · dashmachineDec 17, 2023
- CVE-2025-6131836Monitor
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.
CriticalCVSS 9.1No exploitEPSS 1%emlog · emlogDec 8, 2025
- CVE-2023-139835Monitor
XiaoBingBy TeaCMS upload path traversal
HighCVSS 8.8No exploitEPSS 1%teacms project · teacmsMar 14, 2023
- CVE-2024-282535Monitor
lakernote EasyAdmin saveReportFile path traversal
HighCVSS 8.8No exploitEPSS 1%lakernote · easyadminMar 22, 2024
- CVE-2026-1494734Monitor
Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
HighCVSS 8.6No exploitEPSS 1%frauscher sensortechnik · fds 102Aug 20, 2026
- CVE-2021-2672534Monitor
Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
HighCVSS 8.6No exploitEPSS 1%nozominetworks · central management controlFeb 22, 2021
- CVE-2026-9773034Monitor
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) wi
HighCVSS 8.5No exploitEPSS 1%netgate · pfsense plusSep 25, 2026