Skip to content
Noroxi

CWE-25 · 13 records

Path Traversal: '/../filedir'

CVEs in this class

13 records

  • CVE-2022-20775
    65This week

    Cisco SD-WAN Software Privilege Escalation Vulnerability

    HighCVSS 7.8KEVWeaponizedEPSS 12%

    cisco · catalyst sd-wan managerSep 30, 2022

  • Path traversal via crafted cpio archives in Engrampa archivers

    CriticalCVSS 9.6No exploitEPSS 2%

    mate-desktop · engrampaFeb 5, 2024

  • Cisco SD-WAN Software Privilege Escalation Vulnerabilities

    HighCVSS 7.8Proof of conceptEPSS 1%

    cisco · sd-wan vbond orchestratorSep 30, 2022

  • CVE-2023-6118
    30Monitor

    Path Traversal in Neutron IP Camera

    HighCVSS 7.5No exploitEPSS 1%

    neutron · neu-ipb210-28 firmwareNov 23, 2023

  • CVE-2023-6947
    30Monitor

    Best WordPress Gallery Plugin – FooGallery <= 2.4.16 - Authenticated (Contributor+) Directory Traversal

    HighCVSS 7.7No exploitEPSS 1%

    fooplugins · foogalleryDec 10, 2024

  • CVE-2024-2442
    30Monitor

    Path Traversal vulnerability in Franklin Fueling System EVO 550/5000

    HighCVSS 7.5No exploitEPSS 1%

    franklin fueling system · evo 550Mar 19, 2024

  • CVE-2023-6919
    30Monitor

    Path Traversal in VGuard IP Camera Network Recorder

    HighCVSS 7.5No exploitEPSS 1%

    biges · vg-4c1a-lru firmwareJan 26, 2024

  • Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload with resultant code ex

    HighCVSS 7.2No exploitEPSS 3%

    riello-ups · netman 208Dec 24, 2025

  • SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability.

    MediumCVSS 5.8No exploitEPSS 1%

    sky co., ltd. · skysea client viewAug 25, 2026

  • Denial of service (DoS) vulnerability in the office service.

    MediumCVSS 5.5No exploitEPSS 0%

    huawei · harmonyosOct 11, 2025

  • rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

    MediumCVSS 5.5No exploit

    crates.io · rageDec 18, 2024

  • age vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

    MediumCVSS 5.5No exploit

    Go · filippo.io/ageDec 18, 2024

  • Directory Traversal & Filesystem can be accessed by a non-admin user

    MediumCVSS 5.3No exploitEPSS 1%

    swingmx · swing musicJan 19, 2026

All vulnerability classes