CWE-31 · 10 records
Path Traversal: 'dir\..\..\filename'
CVEs in this class
10 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
63This week | CVE-2024-2044Weaponized | Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4pgadmin · pgadmin 4 · CWE-31 | Critical9.9 | — | 79.5% | Mar 7, 2024 |
36Monitor | CVE-2024-24998No exploit | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitraryivanti · avalanche · CWE-31 | High8.8 | — | 3.2% | Apr 18, 2024 |
35Monitor | CVE-2024-41376No exploit | dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.dzzoffice · dzzoffice · CWE-31 | High8.8 | — | 1.0% | Aug 5, 2024 |
33Monitor | CVE-2026-104810No exploit | Mitel MiVoice Office 400 File Management File Browser path traversal vulnerabilitymitel · mitel mivoice office 400 · CWE-31 | High8.4 | — | 0.4% | 2 days ago |
33Monitor | CVE-2026-104706No exploit | Mitel MiVoice Office 400 view system files path traversalmitel · mitel mivoice office 400 · CWE-31 | High8.4 | — | 0.1% | 2 days ago |
31Monitor | CVE-2024-36857Proof of concept | Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.homebrew · jan · CWE-31 | High7.5 | — | 2.1% | Jun 4, 2024 |
30Monitor | CVE-2024-35431No exploit | ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64.zkteco · zkbio cvsecurity · CWE-31 | High7.5 | — | 1.0% | May 30, 2024 |
30Monitor | CVE-2019-6268No exploit | RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /..CWE-31 | High7.5 | — | 0.8% | Mar 7, 2024 |
30Monitor | CVE-2024-25840No exploit | In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guprestaworld · account manager · CWE-31 | High7.5 | — | 0.6% | Feb 27, 2024 |
22Monitor | CVE-2026-104806No exploit | Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosuremitel · mitel mivoice office 400 · CWE-31 | Medium5.5 | — | 0.3% | 2 days ago |
- CVE-2024-204463This week
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
CriticalCVSS 9.9WeaponizedEPSS 79%pgadmin · pgadmin 4Mar 7, 2024
- CVE-2024-2499836Monitor
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary
HighCVSS 8.8No exploitEPSS 3%ivanti · avalancheApr 18, 2024
- CVE-2024-4137635Monitor
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
HighCVSS 8.8No exploitEPSS 1%dzzoffice · dzzofficeAug 5, 2024
- CVE-2026-10481033Monitor
Mitel MiVoice Office 400 File Management File Browser path traversal vulnerability
HighCVSS 8.4No exploitEPSS 0%mitel · mitel mivoice office 4002 days ago
- CVE-2026-10470633Monitor
Mitel MiVoice Office 400 view system files path traversal
HighCVSS 8.4No exploitEPSS 0%mitel · mitel mivoice office 4002 days ago
- CVE-2024-3685731Monitor
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
HighCVSS 7.5Proof of conceptEPSS 2%homebrew · janJun 4, 2024
- CVE-2024-3543130Monitor
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64.
HighCVSS 7.5No exploitEPSS 1%zkteco · zkbio cvsecurityMay 30, 2024
- CVE-2019-626830Monitor
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /..
HighCVSS 7.5No exploitEPSS 1%Mar 7, 2024
- CVE-2024-2584030Monitor
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a gu
HighCVSS 7.5No exploitEPSS 1%prestaworld · account managerFeb 27, 2024
- CVE-2026-10480622Monitor
Mitel MiVoice Office 400 System Logs Path Traversal Information Disclosure
MediumCVSS 5.5No exploitEPSS 0%mitel · mitel mivoice office 4002 days ago