CWE-27 · 21 records
Path Traversal: 'dir/../../filename'
CVEs in this class
21 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2024-24809Weaponized | Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Typetraccar · traccar · CWE-27 | High8.5 | — | 54.4% | Apr 10, 2024 |
39Monitor | CVE-2024-21896No exploit | The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user.nodejs · node.js · CWE-27 | Critical9.8 | — | 1.3% | Feb 19, 2024 |
35Monitor | CVE-2025-66518No exploit | Apache Kyuubi: Unauthorized directory access due to missing path normalizationapache · kyuubi · CWE-27 | High8.8 | — | 1.0% | Jan 5, 2026 |
34Monitor | CVE-2023-34125No exploit | Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wisonicwall · analytics · CWE-27 | Medium6.5 | — | 25.4% | Jul 12, 2023 |
34Monitor | CVE-2025-10438No exploit | Path Traversal in Yordam BT's Yordam Katalogyordam information technology consulting education and electrical systems industry trade inc. · yordam katalog · CWE-27 | High8.6 | — | 0.4% | Sep 25, 2025 |
31Monitor | CVE-2021-35027No exploit | A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access zyxel · zywall vpn2s firmware · CWE-27 | High7.5 | — | 2.0% | Sep 29, 2021 |
30Monitor | CVE-2024-20348No exploit | A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthcisco · nexus dashboard fabric controller · CWE-27 | High7.5 | — | 0.8% | Apr 3, 2024 |
30Monitor | CVE-2025-58761No exploit | Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`tautulli · tautulli · CWE-27 | High7.5 | — | 0.7% | Sep 9, 2025 |
30Monitor | CVE-2026-76344No exploit | Path Traversal through the Search Dispatch REST API in Splunk Enterprisesplunk · splunk · CWE-27 | High7.7 | — | 0.4% | Aug 19, 2026 |
28Monitor | CVE-2024-43658No exploit | Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.iocharger · iocharger firmware for ac models · CWE-27 | High7.2 | — | 0.5% | Jan 9, 2025 |
26Monitor | CVE-2023-20127No exploit | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Medium6.5 | — | 0.9% | Apr 5, 2023 |
26Monitor | CVE-2023-20129No exploit | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Medium6.5 | — | 0.9% | Apr 5, 2023 |
26Monitor | CVE-2025-52237No exploit | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.sscms · sscms · CWE-27 | Medium6.5 | — | 0.5% | Aug 5, 2025 |
26Monitor | CVE-2023-20130No exploit | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Medium6.5 | — | 0.4% | Apr 5, 2023 |
26Monitor | CVE-2023-20090No exploit | Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerabilitycisco · telepresence collaboration endpoint · CWE-27 | Medium6.7 | — | 0.2% | Nov 15, 2024 |
23Monitor | CVE-2026-20018No exploit | Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerabilitycisco · cisco secure firewall management center (fmc) · CWE-27 | Medium5.9 | — | 0.4% | Mar 4, 2026 |
23Monitor | CVE-2026-17495No exploit | moment vulnerable to Path Traversal via crafted non-string locale namemoment · moment · CWE-27 | Medium5.9 | — | 0.4% | Sep 15, 2026 |
22Monitor | CVE-2025-58292No exploit | Denial of service (DoS) vulnerability in the office service.huawei · harmonyos · CWE-27 | Medium5.5 | — | 0.1% | Oct 11, 2025 |
21Monitor | CVE-2023-20131No exploit | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Medium5.4 | — | 0.6% | Apr 5, 2023 |
20Monitor | CVE-2024-7458No exploit | elunez eladmin Database Management/Deployment Management upload path traversaleladmin · eladmin · CWE-27 | Medium5.1 | — | 0.8% | Aug 4, 2024 |
19Monitor | CVE-2024-25828No exploit | cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.cmseasy · cmseasy · CWE-27 | Medium4.9 | — | 0.6% | Feb 22, 2024 |
- CVE-2024-2480950Plan
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
HighCVSS 8.5WeaponizedEPSS 54%traccar · traccarApr 10, 2024
- CVE-2024-2189639Monitor
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user.
CriticalCVSS 9.8No exploitEPSS 1%nodejs · node.jsFeb 19, 2024
- CVE-2025-6651835Monitor
Apache Kyuubi: Unauthorized directory access due to missing path normalization
HighCVSS 8.8No exploitEPSS 1%apache · kyuubiJan 5, 2026
- CVE-2023-3412534Monitor
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wi
MediumCVSS 6.5No exploitEPSS 25%sonicwall · analyticsJul 12, 2023
- CVE-2025-1043834Monitor
Path Traversal in Yordam BT's Yordam Katalog
HighCVSS 8.6No exploitEPSS 0%yordam information technology consulting education and electrical systems industry trade inc. · yordam katalogSep 25, 2025
- CVE-2021-3502731Monitor
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access
HighCVSS 7.5No exploitEPSS 2%zyxel · zywall vpn2s firmwareSep 29, 2021
- CVE-2024-2034830Monitor
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauth
HighCVSS 7.5No exploitEPSS 1%cisco · nexus dashboard fabric controllerApr 3, 2024
- CVE-2025-5876130Monitor
Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
HighCVSS 7.5No exploitEPSS 1%tautulli · tautulliSep 9, 2025
- CVE-2026-7634430Monitor
Path Traversal through the Search Dispatch REST API in Splunk Enterprise
HighCVSS 7.7No exploitEPSS 0%splunk · splunkAug 19, 2026
- CVE-2024-4365828Monitor
Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.
HighCVSS 7.2No exploitEPSS 1%iocharger · iocharger firmware for ac modelsJan 9, 2025
- CVE-2023-2012726Monitor
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
MediumCVSS 6.5No exploitEPSS 1%cisco · prime infrastructureApr 5, 2023
- CVE-2023-2012926Monitor
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
MediumCVSS 6.5No exploitEPSS 1%cisco · prime infrastructureApr 5, 2023
- CVE-2025-5223726Monitor
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
MediumCVSS 6.5No exploitEPSS 0%sscms · sscmsAug 5, 2025
- CVE-2023-2013026Monitor
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
MediumCVSS 6.5No exploitEPSS 0%cisco · prime infrastructureApr 5, 2023
- CVE-2023-2009026Monitor
Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability
MediumCVSS 6.7No exploitEPSS 0%cisco · telepresence collaboration endpointNov 15, 2024
- CVE-2026-2001823Monitor
Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability
MediumCVSS 5.9No exploitEPSS 0%cisco · cisco secure firewall management center (fmc)Mar 4, 2026
- CVE-2026-1749523Monitor
moment vulnerable to Path Traversal via crafted non-string locale name
MediumCVSS 5.9No exploitEPSS 0%moment · momentSep 15, 2026
- CVE-2025-5829222Monitor
Denial of service (DoS) vulnerability in the office service.
MediumCVSS 5.5No exploitEPSS 0%huawei · harmonyosOct 11, 2025
- CVE-2023-2013121Monitor
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
MediumCVSS 5.4No exploitEPSS 1%cisco · prime infrastructureApr 5, 2023
- CVE-2024-745820Monitor
elunez eladmin Database Management/Deployment Management upload path traversal
MediumCVSS 5.1No exploitEPSS 1%eladmin · eladminAug 4, 2024
- CVE-2024-2582819Monitor
cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
MediumCVSS 4.9No exploitEPSS 1%cmseasy · cmseasyFeb 22, 2024