Skip to content
Noroxi

CWE-27 · 21 records

Path Traversal: 'dir/../../filename'

CVEs in this class

21 records

  • Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type

    HighCVSS 8.5WeaponizedEPSS 54%

    traccar · traccarApr 10, 2024

  • The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user.

    CriticalCVSS 9.8No exploitEPSS 1%

    nodejs · node.jsFeb 19, 2024

  • Apache Kyuubi: Unauthorized directory access due to missing path normalization

    HighCVSS 8.8No exploitEPSS 1%

    apache · kyuubiJan 5, 2026

  • Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wi

    MediumCVSS 6.5No exploitEPSS 25%

    sonicwall · analyticsJul 12, 2023

  • Path Traversal in Yordam BT's Yordam Katalog

    HighCVSS 8.6No exploitEPSS 0%

    yordam information technology consulting education and electrical systems industry trade inc. · yordam katalogSep 25, 2025

  • A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access

    HighCVSS 7.5No exploitEPSS 2%

    zyxel · zywall vpn2s firmwareSep 29, 2021

  • A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauth

    HighCVSS 7.5No exploitEPSS 1%

    cisco · nexus dashboard fabric controllerApr 3, 2024

  • Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`

    HighCVSS 7.5No exploitEPSS 1%

    tautulli · tautulliSep 9, 2025

  • Path Traversal through the Search Dispatch REST API in Splunk Enterprise

    HighCVSS 7.7No exploitEPSS 0%

    splunk · splunkAug 19, 2026

  • Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.

    HighCVSS 7.2No exploitEPSS 1%

    iocharger · iocharger firmware for ac modelsJan 9, 2025

  • Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    MediumCVSS 6.5No exploitEPSS 1%

    cisco · prime infrastructureApr 5, 2023

  • Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    MediumCVSS 6.5No exploitEPSS 1%

    cisco · prime infrastructureApr 5, 2023

  • An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

    MediumCVSS 6.5No exploitEPSS 0%

    sscms · sscmsAug 5, 2025

  • Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    MediumCVSS 6.5No exploitEPSS 0%

    cisco · prime infrastructureApr 5, 2023

  • Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability

    MediumCVSS 6.7No exploitEPSS 0%

    cisco · telepresence collaboration endpointNov 15, 2024

  • Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability

    MediumCVSS 5.9No exploitEPSS 0%

    cisco · cisco secure firewall management center (fmc)Mar 4, 2026

  • moment vulnerable to Path Traversal via crafted non-string locale name

    MediumCVSS 5.9No exploitEPSS 0%

    moment · momentSep 15, 2026

  • Denial of service (DoS) vulnerability in the office service.

    MediumCVSS 5.5No exploitEPSS 0%

    huawei · harmonyosOct 11, 2025

  • Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    MediumCVSS 5.4No exploitEPSS 1%

    cisco · prime infrastructureApr 5, 2023

  • CVE-2024-7458
    20Monitor

    elunez eladmin Database Management/Deployment Management upload path traversal

    MediumCVSS 5.1No exploitEPSS 1%

    eladmin · eladminAug 4, 2024

  • cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

    MediumCVSS 4.9No exploitEPSS 1%

    cmseasy · cmseasyFeb 22, 2024

All vulnerability classes