Skip to content
Noroxi

CWE-24 · 103 records

Path Traversal: '../filedir'

CVEs in this class

103 records

  • CVE-2025-27920
    66This week

    Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling.

    HighCVSS 8.8KEVWeaponizedEPSS 2%

    srimax · output messengerMay 5, 2025

  • sjqzhang go-fastdfs File Upload uploa upload path traversal

    CriticalCVSS 9.8No exploitEPSS 4%

    go-fastdfs project · go-fastdfsApr 2, 2023

  • An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attacke

    CriticalCVSS 9.8No exploitEPSS 2%

    academiaerp · student information systemApr 26, 2025

  • CVE-2023-3057
    39Monitor

    YFCMF Ajax.php path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    iuok · yfcmf-tp6Jun 2, 2023

  • CVE-2023-3056
    39Monitor

    YFCMF index.php path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    iuok · yfcmf-tp6Jun 2, 2023

  • CVE-2024-0989
    39Monitor

    Sichuan Yougou Technology KuERP Service.php del_sn_db path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    kuerp project · kuerpJan 28, 2024

  • CVE-2024-0417
    39Monitor

    DeShang DSShop MemberAuth.php path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    csdeshang · dsshopJan 11, 2024

  • CVE-2024-0416
    39Monitor

    DeShang DSMall MemberAuth.php path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    csdeshang · dsmallJan 11, 2024

  • CVE-2023-7134
    39Monitor

    SourceCodester Medicine Tracking System path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · medicine tracker systemDec 28, 2023

  • In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    infodraw · pmrs-102 firmwareApr 19, 2025

  • CVE-2024-2563
    39Monitor

    PandaXGO PandaX upload.go DeleteImage path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    pandax · pandaxMar 17, 2024

  • CVE-2023-7058
    39Monitor

    SourceCodester Simple Student Attendance System path traversal

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · simple student attendance systemDec 22, 2023

  • A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attack

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    fortinet · fortisandboxApr 14, 2026

  • A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpu

    HighCVSS 8.6No exploitEPSS 11%

    d-link · dsr-150Oct 21, 2025

  • Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.

    CriticalCVSS 9.4No exploitEPSS 0%

    webmin · webminMay 27, 2026

  • Apache Hadoop Privilege escalation vulnerability

    HighCVSS 8.8No exploitEPSS 4%

    apache · hadoopJun 15, 2022

  • KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal

    HighCVSS 8.8Proof of conceptEPSS 3%

    xorux · lpar2rrdJul 28, 2025

  • CVE-2020-7882
    36Monitor

    anySign directory traversal vulnerability

    CriticalCVSS 9.1Proof of conceptEPSS 1%

    hancom · anysign4pcNov 22, 2021

  • CVE-2023-6900
    36Monitor

    rmountjoy92 DashMachine delete_file path traversal

    CriticalCVSS 9.1No exploitEPSS 1%

    rmountjoy92 · dashmachineDec 17, 2023

  • Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.

    CriticalCVSS 9.1No exploitEPSS 1%

    emlog · emlogDec 8, 2025

  • CVE-2023-1398
    35Monitor

    XiaoBingBy TeaCMS upload path traversal

    HighCVSS 8.8No exploitEPSS 1%

    teacms project · teacmsMar 14, 2023

  • CVE-2024-2825
    35Monitor

    lakernote EasyAdmin saveReportFile path traversal

    HighCVSS 8.8No exploitEPSS 1%

    lakernote · easyadminMar 22, 2024

  • Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file

    HighCVSS 8.6No exploitEPSS 1%

    frauscher sensortechnik · fds 102Aug 20, 2026

  • Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4

    HighCVSS 8.6No exploitEPSS 1%

    nozominetworks · central management controlFeb 22, 2021

  • In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) wi

    HighCVSS 8.5No exploitEPSS 1%

    netgate · pfsense plusSep 25, 2026

All vulnerability classes