CWE-25 · 13 records
Path Traversal: '/../filedir'
CVEs in this class
13 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
65This week | CVE-2022-20775Weaponized | Cisco SD-WAN Software Privilege Escalation Vulnerabilitycisco · catalyst sd-wan manager · CWE-25 | High7.8 | KEV | 12.5% | Sep 30, 2022 |
38Monitor | CVE-2023-52138No exploit | Path traversal via crafted cpio archives in Engrampa archiversmate-desktop · engrampa · CWE-25 | Critical9.6 | — | 1.7% | Feb 5, 2024 |
31Monitor | CVE-2022-20818Proof of concept | Cisco SD-WAN Software Privilege Escalation Vulnerabilitiescisco · sd-wan vbond orchestrator · CWE-25 | High7.8 | — | 0.6% | Sep 30, 2022 |
30Monitor | CVE-2023-6118No exploit | Path Traversal in Neutron IP Cameraneutron · neu-ipb210-28 firmware · CWE-25 | High7.5 | — | 0.8% | Nov 23, 2023 |
30Monitor | CVE-2023-6947No exploit | Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversalfooplugins · foogallery · CWE-25 | High7.7 | — | 0.8% | Dec 10, 2024 |
30Monitor | CVE-2024-2442No exploit | Path Traversal vulnerability in Franklin Fueling System EVO 550/5000franklin fueling system · evo 550 · CWE-25 | High7.5 | — | 0.7% | Mar 19, 2024 |
30Monitor | CVE-2023-6919No exploit | Path Traversal in VGuard IP Camera Network Recorderbiges · vg-4c1a-lru firmware · CWE-25 | High7.5 | — | 0.6% | Jan 26, 2024 |
29Monitor | CVE-2025-68916No exploit | Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code exriello-ups · netman 208 · CWE-25 | High7.2 | — | 2.6% | Dec 24, 2025 |
23Monitor | CVE-2026-68959No exploit | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability.sky co., ltd. · skysea client view · CWE-25 | Medium5.8 | — | 0.7% | Aug 25, 2026 |
22Monitor | CVE-2025-58286No exploit | Denial of service (DoS) vulnerability in the office service.huawei · harmonyos · CWE-25 | Medium5.5 | — | 0.1% | Oct 11, 2025 |
22Monitor | GHSA-4fg7-vxc8-qx5wNo exploit | rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary executioncrates.io · rage · CWE-25 | Medium5.5 | — | — | Dec 18, 2024 |
22Monitor | GHSA-32gq-x56h-299cNo exploit | age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary executionGo · filippo.io/age · CWE-25 | Medium5.5 | — | — | Dec 18, 2024 |
21Monitor | CVE-2026-23877No exploit | Directory Traversal & Filesystem can be accessed by a non-admin userswingmx · swing music · CWE-25 | Medium5.3 | — | 0.6% | Jan 19, 2026 |
- CVE-2022-2077565This week
Cisco SD-WAN Software Privilege Escalation Vulnerability
HighCVSS 7.8KEVWeaponizedEPSS 12%cisco · catalyst sd-wan managerSep 30, 2022
- CVE-2023-5213838Monitor
Path traversal via crafted cpio archives in Engrampa archivers
CriticalCVSS 9.6No exploitEPSS 2%mate-desktop · engrampaFeb 5, 2024
- CVE-2022-2081831Monitor
Cisco SD-WAN Software Privilege Escalation Vulnerabilities
HighCVSS 7.8Proof of conceptEPSS 1%cisco · sd-wan vbond orchestratorSep 30, 2022
- CVE-2023-611830Monitor
Path Traversal in Neutron IP Camera
HighCVSS 7.5No exploitEPSS 1%neutron · neu-ipb210-28 firmwareNov 23, 2023
- CVE-2023-694730Monitor
Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal
HighCVSS 7.7No exploitEPSS 1%fooplugins · foogalleryDec 10, 2024
- CVE-2024-244230Monitor
Path Traversal vulnerability in Franklin Fueling System EVO 550/5000
HighCVSS 7.5No exploitEPSS 1%franklin fueling system · evo 550Mar 19, 2024
- CVE-2023-691930Monitor
Path Traversal in VGuard IP Camera Network Recorder
HighCVSS 7.5No exploitEPSS 1%biges · vg-4c1a-lru firmwareJan 26, 2024
- CVE-2025-6891629Monitor
Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code ex
HighCVSS 7.2No exploitEPSS 3%riello-ups · netman 208Dec 24, 2025
- CVE-2026-6895923Monitor
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability.
MediumCVSS 5.8No exploitEPSS 1%sky co., ltd. · skysea client viewAug 25, 2026
- CVE-2025-5828622Monitor
Denial of service (DoS) vulnerability in the office service.
MediumCVSS 5.5No exploitEPSS 0%huawei · harmonyosOct 11, 2025
- GHSA-4fg7-vxc8-qx5w22Monitor
rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
MediumCVSS 5.5No exploitcrates.io · rageDec 18, 2024
- GHSA-32gq-x56h-299c22Monitor
age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution
MediumCVSS 5.5No exploitGo · filippo.io/ageDec 18, 2024
- CVE-2026-2387721Monitor
Directory Traversal & Filesystem can be accessed by a non-admin user
MediumCVSS 5.3No exploitEPSS 1%swingmx · swing musicJan 19, 2026