CWE-29 · 63 records
Path Traversal: '\..\filename'
CVEs in this class
63 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
60This week | CVE-2023-1177Proof of concept | Path Traversal: '\..\filename' in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical9.8 | — | 69.7% | Mar 24, 2023 |
57Plan | CVE-2023-6909Proof of concept | Path Traversal: '\..\filename' in mlflow/mlflowlfprojects · mlflow · CWE-29 | High7.5 | — | 89.7% | Dec 18, 2023 |
55Plan | CVE-2024-6396Proof of concept | Arbitrary File Overwrite and Data Exfiltration in aimhubio/aimaimstack · aim · CWE-29 | Critical9.8 | — | 53.1% | Jul 11, 2024 |
50Plan | CVE-2024-2083Proof of concept | Directory Traversal in zenml-io/zenmlzenml · zenml · CWE-29 | Critical9.9 | — | 37.5% | Apr 15, 2024 |
49Plan | CVE-2024-4320Proof of concept | Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webuilollms · lollms web ui · CWE-29 | Critical9.8 | — | 34.4% | Jun 6, 2024 |
47Plan | CVE-2024-3429No exploit | Path Traversal in parisneo/lollmslollms · lollms · CWE-29 | Critical9.8 | — | 28.3% | Jun 6, 2024 |
43Plan | CVE-2024-3848Proof of concept | Path Traversal Bypass in mlflow/mlflowlfprojects · mlflow · CWE-29 | High7.5 | — | 43.3% | May 16, 2024 |
43Plan | CVE-2023-1034No exploit | Path Traversal: '\..\filename' in salesagility/suitecrmsalesagility · suitecrm · CWE-29 | High8.8 | — | 26.2% | Feb 24, 2023 |
41Plan | CVE-2023-6021Proof of concept | Ray Log File Local File Includeray project · ray · CWE-29 | High7.5 | — | 37.1% | Nov 16, 2023 |
41Plan | CVE-2023-2780Proof of concept | Path Traversal: '\..\filename' in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical9.8 | — | 6.4% | May 17, 2023 |
40Plan | CVE-2023-6975No exploit | Path Traversal: '\..\filename'lfprojects · mlflow · CWE-29 | Critical9.8 | — | 2.0% | Dec 20, 2023 |
40Plan | CVE-2024-2360No exploit | Path Traversal leading to Remote Code Execution in parisneo/lollms-webuilollms · lollms web ui · CWE-29 | Critical9.8 | — | 1.9% | Jun 6, 2024 |
40Plan | CVE-2025-15036No exploit | Path Traversal Vulnerability in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical10.0 | — | 0.6% | Mar 29, 2026 |
39Monitor | CVE-2024-4322Proof of concept | Path Traversal in parisneo/lollms-webuilollms · lollms web ui · CWE-29 | High7.5 | — | 31.0% | May 16, 2024 |
39Monitor | CVE-2024-2624No exploit | Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webuilollms · lollms web ui · CWE-29 | Critical9.8 | — | 1.4% | Jun 6, 2024 |
39Monitor | CVE-2024-5443No exploit | Remote Code Execution via Path Traversal in parisneo/lollmsparisneo · parisneo/lollms · CWE-29 | Critical9.8 | — | 1.2% | Jun 22, 2024 |
39Monitor | CVE-2024-2358No exploit | Path Traversal leading to Remote Code Execution in parisneo/lollms-webuilollms · lollms web ui · CWE-29 | Critical9.8 | — | 1.1% | May 16, 2024 |
38Monitor | CVE-2023-0104No exploit | The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.weintek · easybuilder pro · CWE-29 | High7.8 | — | 21.8% | Feb 22, 2023 |
38Monitor | CVE-2024-2356No exploit | Remote Code Execution due to LFI in '/reinstall_extension' in parisneo/lollms-webuiparisneo · parisneo/lollms-webui · CWE-29 | Critical9.6 | — | 0.8% | Feb 2, 2026 |
38Monitor | CVE-2024-2361No exploit | Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webuilollms · lollms web ui · CWE-29 | Critical9.6 | — | 0.6% | May 16, 2024 |
37Monitor | CVE-2024-2928Proof of concept | Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflowlfprojects · mlflow · CWE-29 | High7.5 | — | 21.8% | Jun 6, 2024 |
37Monitor | CVE-2024-3573No exploit | Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflowlfprojects · mlflow · CWE-29 | Critical9.3 | — | 0.7% | Apr 15, 2024 |
36Monitor | CVE-2024-34470Proof of concept | An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18.hsclabs · mailinspector · CWE-29 | High8.6 | — | 6.7% | May 6, 2024 |
36Monitor | CVE-2024-11170No exploit | Path Traversal in danny-avila/librechatlibrechat · librechat · CWE-29 | High8.8 | — | 1.8% | Mar 20, 2025 |
36Monitor | CVE-2024-8537No exploit | Path Traversal in modelscope/agentscopemodelscope · agentscope · CWE-29 | Critical9.1 | — | 1.0% | Mar 20, 2025 |
- CVE-2023-117760This week
Path Traversal: '\..\filename' in mlflow/mlflow
CriticalCVSS 9.8Proof of conceptEPSS 70%lfprojects · mlflowMar 24, 2023
- CVE-2023-690957Plan
Path Traversal: '\..\filename' in mlflow/mlflow
HighCVSS 7.5Proof of conceptEPSS 90%lfprojects · mlflowDec 18, 2023
- CVE-2024-639655Plan
Arbitrary File Overwrite and Data Exfiltration in aimhubio/aim
CriticalCVSS 9.8Proof of conceptEPSS 53%aimstack · aimJul 11, 2024
- CVE-2024-208350Plan
Directory Traversal in zenml-io/zenml
CriticalCVSS 9.9Proof of conceptEPSS 37%zenml · zenmlApr 15, 2024
- CVE-2024-432049Plan
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
CriticalCVSS 9.8Proof of conceptEPSS 34%lollms · lollms web uiJun 6, 2024
- CVE-2024-342947Plan
Path Traversal in parisneo/lollms
CriticalCVSS 9.8No exploitEPSS 28%lollms · lollmsJun 6, 2024
- CVE-2024-384843Plan
Path Traversal Bypass in mlflow/mlflow
HighCVSS 7.5Proof of conceptEPSS 43%lfprojects · mlflowMay 16, 2024
- CVE-2023-103443Plan
Path Traversal: '\..\filename' in salesagility/suitecrm
HighCVSS 8.8No exploitEPSS 26%salesagility · suitecrmFeb 24, 2023
- CVE-2023-602141Plan
Ray Log File Local File Include
HighCVSS 7.5Proof of conceptEPSS 37%ray project · rayNov 16, 2023
- CVE-2023-278041Plan
Path Traversal: '\..\filename' in mlflow/mlflow
CriticalCVSS 9.8Proof of conceptEPSS 6%lfprojects · mlflowMay 17, 2023
- CVE-2023-697540Plan
Path Traversal: '\..\filename'
CriticalCVSS 9.8No exploitEPSS 2%lfprojects · mlflowDec 20, 2023
- CVE-2024-236040Plan
Path Traversal leading to Remote Code Execution in parisneo/lollms-webui
CriticalCVSS 9.8No exploitEPSS 2%lollms · lollms web uiJun 6, 2024
- CVE-2025-1503640Plan
Path Traversal Vulnerability in mlflow/mlflow
CriticalCVSS 10.0No exploitEPSS 1%lfprojects · mlflowMar 29, 2026
- CVE-2024-432239Monitor
Path Traversal in parisneo/lollms-webui
HighCVSS 7.5Proof of conceptEPSS 31%lollms · lollms web uiMay 16, 2024
- CVE-2024-262439Monitor
Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webui
CriticalCVSS 9.8No exploitEPSS 1%lollms · lollms web uiJun 6, 2024
- CVE-2024-544339Monitor
Remote Code Execution via Path Traversal in parisneo/lollms
CriticalCVSS 9.8No exploitEPSS 1%parisneo · parisneo/lollmsJun 22, 2024
- CVE-2024-235839Monitor
Path Traversal leading to Remote Code Execution in parisneo/lollms-webui
CriticalCVSS 9.8No exploitEPSS 1%lollms · lollms web uiMay 16, 2024
- CVE-2023-010438Monitor
The listed versions for Weintek EasyBuilder Pro are vulnerable to a ZipSlip attack caused by decompiling a malicious project file.
HighCVSS 7.8No exploitEPSS 22%weintek · easybuilder proFeb 22, 2023
- CVE-2024-235638Monitor
Remote Code Execution due to LFI in '/reinstall_extension' in parisneo/lollms-webui
CriticalCVSS 9.6No exploitEPSS 1%parisneo · parisneo/lollms-webuiFeb 2, 2026
- CVE-2024-236138Monitor
Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webui
CriticalCVSS 9.6No exploitEPSS 1%lollms · lollms web uiMay 16, 2024
- CVE-2024-292837Monitor
Local File Inclusion (LFI) via URI Fragment Parsing in mlflow/mlflow
HighCVSS 7.5Proof of conceptEPSS 22%lfprojects · mlflowJun 6, 2024
- CVE-2024-357337Monitor
Local File Inclusion (LFI) via Scheme Confusion in mlflow/mlflow
CriticalCVSS 9.3No exploitEPSS 1%lfprojects · mlflowApr 15, 2024
- CVE-2024-3447036Monitor
An issue was discovered in HSC Mailinspector 5.2.17-3 through v.5.2.18.
HighCVSS 8.6Proof of conceptEPSS 7%hsclabs · mailinspectorMay 6, 2024
- CVE-2024-1117036Monitor
Path Traversal in danny-avila/librechat
HighCVSS 8.8No exploitEPSS 2%librechat · librechatMar 20, 2025
- CVE-2024-853736Monitor
Path Traversal in modelscope/agentscope
CriticalCVSS 9.1No exploitEPSS 1%modelscope · agentscopeMar 20, 2025