CWE-23 · 462 записей
Relative Path Traversal
CVE этого класса
462 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
97Срочно | CVE-2021-40870Готовый эксплойт | An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922.aviatrix · controller · CWE-23 | Критическая9,8 | KEV | 93,0 % | 13 сент. 2021 г. |
97Срочно | CVE-2025-64446Готовый эксплойт | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9fortinet · fortiweb · CWE-23 | Критическая9,8 | KEV | 91,8 % | 14 нояб. 2025 г. |
89Срочно | CVE-2024-27199Готовый эксплойт | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possiblejetbrains · teamcity · CWE-23 | Высокая7,3 | KEV | 100,0 % | 4 мар. 2024 г. |
89Срочно | CVE-2020-5410Готовый эксплойт | Directory Traversal with spring-cloud-config-servervmware · spring cloud config · CWE-23 | Высокая7,5 | KEV | 95,6 % | 2 июн. 2020 г. |
56В плане | CVE-2026-34926Готовый эксплойт | A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key tabletrendmicro · apex one · CWE-23 | Средняя6,7 | KEV | 0,5 % | 21 мая 2026 г. |
50В плане | CVE-2022-29844Эксплойта нет | Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftpwesterndigital · my cloud pr2100 firmware · CWE-23 | Критическая9,8 | — | 36,4 % | 26 янв. 2023 г. |
49В плане | CVE-2025-55752Proof of concept | Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabledapache · tomcat · CWE-23 | Высокая7,5 | — | 64,4 % | 27 окт. 2025 г. |
47В плане | CVE-2020-5405Proof of concept | Directory Traversal with spring-cloud-config-servervmware · spring cloud config · CWE-23 | Средняя6,5 | — | 68,8 % | 5 мар. 2020 г. |
46В плане | CVE-2023-34990Proof of concept | A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized cfortinet · fortiwlm · CWE-23 | Критическая9,8 | — | 24,8 % | 18 дек. 2024 г. |
45В плане | CVE-2020-17518Proof of concept | Apache Flink directory traversal attack: remote file writing through the REST APIapache · flink · CWE-23 | Высокая7,5 | — | 51,4 % | 5 янв. 2021 г. |
44В плане | CVE-2022-23854Proof of concept | AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated useraveva · intouch access anywhere · CWE-23 | Высокая7,5 | — | 46,0 % | 23 дек. 2022 г. |
44В плане | CVE-2022-2139Эксплойта нет | The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary coadvantech · iview · CWE-23 | Критическая9,8 | — | 15,6 % | 22 июл. 2022 г. |
43В плане | CVE-2024-2053Proof of concept | Artica Proxy Unauthenticated LFI Protection Bypass Vulnerabilityarticatech · artica proxy · CWE-23 | Высокая7,5 | — | 44,6 % | 20 мар. 2024 г. |
43В плане | CVE-2026-23734Эксплойта нет | XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slashxwiki · xwiki-commons · CWE-23 | Критическая9,3 | — | 19,6 % | 20 мая 2026 г. |
42В плане | CVE-2021-43555Эксплойта нет | mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulmyscada · mydesigner · CWE-23 | Высокая7,8 | — | 38,2 % | 19 нояб. 2021 г. |
42В плане | CVE-2025-34510Готовый эксплойт | Sitecore XM, XC, and XP Post-Auth RCE via Zip Slipsitecore · experience commerce · CWE-23 | Высокая8,8 | — | 24,3 % | 17 июн. 2025 г. |
42В плане | CVE-2020-8271Эксплойта нет | Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8citrix · sd-wan · CWE-23 | Критическая9,8 | — | 11,1 % | 15 нояб. 2020 г. |
42В плане | CVE-2024-24578Готовый эксплойт | RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Uploadraspberrymatic · raspberrymatic · CWE-23 | Критическая9,8 | — | 8,7 % | 18 мар. 2024 г. |
41В плане | CVE-2020-25176Эксплойта нет | Rockwell Automation ISaGRAF5 Runtime Relative Path Traversalschneider-electric · easergy t300 firmware · CWE-23 | Критическая9,8 | — | 6,4 % | 18 мар. 2022 г. |
41В плане | CVE-2023-6825Proof of concept | File Manager And File Manager Pro (Multiple Versions) - Directory Traversalmndpsingh287 · file manager · CWE-23 | Критическая9,9 | — | 6,0 % | 13 мар. 2024 г. |
41В плане | CVE-2025-47445Proof of concept | WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerabilitythemewinter · eventin · CWE-23 | Критическая9,8 | — | 5,1 % | 14 мая 2025 г. |
41В плане | CVE-2012-6069Эксплойта нет | 3S CoDeSys Relative Path Traversal3s-software · codesys runtime system · CWE-23 | Критическая10,0 | — | 2,6 % | 21 янв. 2013 г. |
40В плане | CVE-2020-10619Эксплойта нет | An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.advantech · webaccess\/nms · CWE-23 | Критическая9,1 | — | 14,3 % | 9 апр. 2020 г. |
40В плане | CVE-2020-12006Эксплойта нет | Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.advantech · webaccess · CWE-23 | Критическая9,8 | — | 3,7 % | 8 мая 2020 г. |
40В плане | CVE-2020-27304Эксплойта нет | The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-bacivetweb project · civetweb · CWE-23 | Критическая9,8 | — | 3,2 % | 21 окт. 2021 г. |
- CVE-2021-4087097Срочно
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %aviatrix · controller13 сент. 2021 г.
- CVE-2025-6444697Срочно
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %fortinet · fortiweb14 нояб. 2025 г.
- CVE-2024-2719989Срочно
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 100 %jetbrains · teamcity4 мар. 2024 г.
- CVE-2020-541089Срочно
Directory Traversal with spring-cloud-config-server
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 96 %vmware · spring cloud config2 июн. 2020 г.
- CVE-2026-3492656В плане
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table
СредняяCVSS 6,7KEVГотовый эксплойтEPSS 1 %trendmicro · apex one21 мая 2026 г.
- CVE-2022-2984450В плане
Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftp
КритическаяCVSS 9,8Эксплойта нетEPSS 36 %westerndigital · my cloud pr2100 firmware26 янв. 2023 г.
- CVE-2025-5575249В плане
Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
ВысокаяCVSS 7,5Proof of conceptEPSS 64 %apache · tomcat27 окт. 2025 г.
- CVE-2020-540547В плане
Directory Traversal with spring-cloud-config-server
СредняяCVSS 6,5Proof of conceptEPSS 69 %vmware · spring cloud config5 мар. 2020 г.
- CVE-2023-3499046В плане
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized c
КритическаяCVSS 9,8Proof of conceptEPSS 25 %fortinet · fortiwlm18 дек. 2024 г.
- CVE-2020-1751845В плане
Apache Flink directory traversal attack: remote file writing through the REST API
ВысокаяCVSS 7,5Proof of conceptEPSS 51 %apache · flink5 янв. 2021 г.
- CVE-2022-2385444В плане
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user
ВысокаяCVSS 7,5Proof of conceptEPSS 46 %aveva · intouch access anywhere23 дек. 2022 г.
- CVE-2022-213944В плане
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co
КритическаяCVSS 9,8Эксплойта нетEPSS 16 %advantech · iview22 июл. 2022 г.
- CVE-2024-205343В плане
Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability
ВысокаяCVSS 7,5Proof of conceptEPSS 45 %articatech · artica proxy20 мар. 2024 г.
- CVE-2026-2373443В плане
XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash
КритическаяCVSS 9,3Эксплойта нетEPSS 20 %xwiki · xwiki-commons20 мая 2026 г.
- CVE-2021-4355542В плане
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vul
ВысокаяCVSS 7,8Эксплойта нетEPSS 38 %myscada · mydesigner19 нояб. 2021 г.
- CVE-2025-3451042В плане
Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip
ВысокаяCVSS 8,8Готовый эксплойтEPSS 24 %sitecore · experience commerce17 июн. 2025 г.
- CVE-2020-827142В плане
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8
КритическаяCVSS 9,8Эксплойта нетEPSS 11 %citrix · sd-wan15 нояб. 2020 г.
- CVE-2024-2457842В плане
RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload
КритическаяCVSS 9,8Готовый эксплойтEPSS 9 %raspberrymatic · raspberrymatic18 мар. 2024 г.
- CVE-2020-2517641В плане
Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %schneider-electric · easergy t300 firmware18 мар. 2022 г.
- CVE-2023-682541В плане
File Manager And File Manager Pro (Multiple Versions) - Directory Traversal
КритическаяCVSS 9,9Proof of conceptEPSS 6 %mndpsingh287 · file manager13 мар. 2024 г.
- CVE-2025-4744541В плане
WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 5 %themewinter · eventin14 мая 2025 г.
- CVE-2012-606941В плане
3S CoDeSys Relative Path Traversal
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %3s-software · codesys runtime system21 янв. 2013 г.
- CVE-2020-1061940В плане
An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.
КритическаяCVSS 9,1Эксплойта нетEPSS 14 %advantech · webaccess\/nms9 апр. 2020 г.
- CVE-2020-1200640В плане
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %advantech · webaccess8 мая 2020 г.
- CVE-2020-2730440В плане
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-ba
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %civetweb project · civetweb21 окт. 2021 г.