CWE-24 · 101 записей
Path Traversal: '../filedir'
CVE этого класса
101 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2025-27920Готовый эксплойт | Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling.srimax · output messenger · CWE-24 | Высокая8,8 | KEV | 1,9 % | 5 мая 2025 г. |
40В плане | CVE-2023-1800Эксплойта нет | sjqzhang go-fastdfs File Upload uploa upload path traversalgo-fastdfs project · go-fastdfs · CWE-24 | Критическая9,8 | — | 3,6 % | 2 апр. 2023 г. |
39Наблюдать | CVE-2024-53636Эксплойта нет | An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attackeacademiaerp · student information system · CWE-24 | Критическая9,8 | — | 1,6 % | 26 апр. 2025 г. |
39Наблюдать | CVE-2023-3057Эксплойта нет | YFCMF Ajax.php path traversaliuok · yfcmf-tp6 · CWE-24 | Критическая9,8 | — | 1,2 % | 2 июн. 2023 г. |
39Наблюдать | CVE-2023-3056Эксплойта нет | YFCMF index.php path traversaliuok · yfcmf-tp6 · CWE-24 | Критическая9,8 | — | 1,2 % | 2 июн. 2023 г. |
39Наблюдать | CVE-2024-0989Эксплойта нет | Sichuan Yougou Technology KuERP Service.php del_sn_db path traversalkuerp project · kuerp · CWE-24 | Критическая9,8 | — | 1,2 % | 28 янв. 2024 г. |
39Наблюдать | CVE-2024-0417Эксплойта нет | DeShang DSShop MemberAuth.php path traversalcsdeshang · dsshop · CWE-24 | Критическая9,8 | — | 1,1 % | 11 янв. 2024 г. |
39Наблюдать | CVE-2023-7134Эксплойта нет | SourceCodester Medicine Tracking System path traversaloretnom23 · medicine tracker system · CWE-24 | Критическая9,8 | — | 0,9 % | 28 дек. 2023 г. |
39Наблюдать | CVE-2024-0416Эксплойта нет | DeShang DSMall MemberAuth.php path traversalcsdeshang · dsmall · CWE-24 | Критическая9,8 | — | 0,9 % | 11 янв. 2024 г. |
39Наблюдать | CVE-2025-43928Эксплойта нет | In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversalinfodraw · pmrs-102 firmware · CWE-24 | Критическая9,8 | — | 0,9 % | 19 апр. 2025 г. |
39Наблюдать | CVE-2024-2563Эксплойта нет | PandaXGO PandaX upload.go DeleteImage path traversalpandax · pandax · CWE-24 | Критическая9,8 | — | 0,9 % | 17 мар. 2024 г. |
39Наблюдать | CVE-2023-7058Эксплойта нет | SourceCodester Simple Student Attendance System path traversaloretnom23 · simple student attendance system · CWE-24 | Критическая9,8 | — | 0,7 % | 22 дек. 2023 г. |
39Наблюдать | CVE-2026-39813Proof of concept | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attackfortinet · fortisandbox · CWE-24 | Критическая9,8 | — | 0,7 % | 14 апр. 2026 г. |
37Наблюдать | CVE-2025-60344Эксплойта нет | A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpud-link · dsr-150 · CWE-24 | Высокая8,6 | — | 10,9 % | 21 окт. 2025 г. |
37Наблюдать | CVE-2026-49103Эксплойта нет | Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.webmin · webmin · CWE-24 | Критическая9,4 | — | 0,5 % | 27 мая 2026 г. |
36Наблюдать | CVE-2021-33036Эксплойта нет | Apache Hadoop Privilege escalation vulnerabilityapache · hadoop · CWE-24 | Высокая8,8 | — | 3,9 % | 15 июн. 2022 г. |
36Наблюдать | CVE-2025-54769Proof of concept | KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversalxorux · lpar2rrd · CWE-24 | Высокая8,8 | — | 3,3 % | 28 июл. 2025 г. |
36Наблюдать | CVE-2020-7882Proof of concept | anySign directory traversal vulnerabilityhancom · anysign4pc · CWE-24 | Критическая9,1 | — | 1,3 % | 22 нояб. 2021 г. |
36Наблюдать | CVE-2023-6900Эксплойта нет | rmountjoy92 DashMachine delete_file path traversalrmountjoy92 · dashmachine · CWE-24 | Критическая9,1 | — | 1,1 % | 17 дек. 2023 г. |
36Наблюдать | CVE-2025-61318Эксплойта нет | Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.emlog · emlog · CWE-24 | Критическая9,1 | — | 0,7 % | 8 дек. 2025 г. |
35Наблюдать | CVE-2023-1398Эксплойта нет | XiaoBingBy TeaCMS upload path traversalteacms project · teacms · CWE-24 | Высокая8,8 | — | 1,0 % | 14 мар. 2023 г. |
35Наблюдать | CVE-2024-2825Эксплойта нет | lakernote EasyAdmin saveReportFile path traversallakernote · easyadmin · CWE-24 | Высокая8,8 | — | 0,7 % | 22 мар. 2024 г. |
34Наблюдать | CVE-2026-14947Эксплойта нет | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP filefrauscher sensortechnik · fds 102 · CWE-24 | Высокая8,6 | — | 1,5 % | 20 авг. 2026 г. |
34Наблюдать | CVE-2021-26725Эксплойта нет | Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4nozominetworks · central management control · CWE-24 | Высокая8,6 | — | 1,1 % | 22 февр. 2021 г. |
34Наблюдать | CVE-2026-97730Эксплойта нет | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) winetgate · pfsense plus · CWE-24 | Высокая8,5 | — | 1,0 % | 5 дней назад |
- CVE-2025-2792066На этой неделе
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 2 %srimax · output messenger5 мая 2025 г.
- CVE-2023-180040В плане
sjqzhang go-fastdfs File Upload uploa upload path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %go-fastdfs project · go-fastdfs2 апр. 2023 г.
- CVE-2024-5363639Наблюдать
An arbitrary file upload vulnerability via writefile.php of Serosoft Academia Student Information System (SIS) EagleR-1.0.118 allows attacke
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %academiaerp · student information system26 апр. 2025 г.
- CVE-2023-305739Наблюдать
YFCMF Ajax.php path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iuok · yfcmf-tp62 июн. 2023 г.
- CVE-2023-305639Наблюдать
YFCMF index.php path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %iuok · yfcmf-tp62 июн. 2023 г.
- CVE-2024-098939Наблюдать
Sichuan Yougou Technology KuERP Service.php del_sn_db path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %kuerp project · kuerp28 янв. 2024 г.
- CVE-2024-041739Наблюдать
DeShang DSShop MemberAuth.php path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %csdeshang · dsshop11 янв. 2024 г.
- CVE-2023-713439Наблюдать
SourceCodester Medicine Tracking System path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · medicine tracker system28 дек. 2023 г.
- CVE-2024-041639Наблюдать
DeShang DSMall MemberAuth.php path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %csdeshang · dsmall11 янв. 2024 г.
- CVE-2025-4392839Наблюдать
In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %infodraw · pmrs-102 firmware19 апр. 2025 г.
- CVE-2024-256339Наблюдать
PandaXGO PandaX upload.go DeleteImage path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %pandax · pandax17 мар. 2024 г.
- CVE-2023-705839Наблюдать
SourceCodester Simple Student Attendance System path traversal
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %oretnom23 · simple student attendance system22 дек. 2023 г.
- CVE-2026-3981339Наблюдать
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attack
КритическаяCVSS 9,8Proof of conceptEPSS 1 %fortinet · fortisandbox14 апр. 2026 г.
- CVE-2025-6034437Наблюдать
A path traversal (directory traversal) vulnerability in D-Link DSR series routers allows unauthenticated remote attackers to manipulate inpu
ВысокаяCVSS 8,6Эксплойта нетEPSS 11 %d-link · dsr-15021 окт. 2025 г.
- CVE-2026-4910337Наблюдать
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component.
КритическаяCVSS 9,4Эксплойта нетEPSS 0 %webmin · webmin27 мая 2026 г.
- CVE-2021-3303636Наблюдать
Apache Hadoop Privilege escalation vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %apache · hadoop15 июн. 2022 г.
- CVE-2025-5476936Наблюдать
KL-001-2025-016: Xorux LPAR2RRD File Upload Directory Traversal
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %xorux · lpar2rrd28 июл. 2025 г.
- CVE-2020-788236Наблюдать
anySign directory traversal vulnerability
КритическаяCVSS 9,1Proof of conceptEPSS 1 %hancom · anysign4pc22 нояб. 2021 г.
- CVE-2023-690036Наблюдать
rmountjoy92 DashMachine delete_file path traversal
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %rmountjoy92 · dashmachine17 дек. 2023 г.
- CVE-2025-6131836Наблюдать
Emlog Pro 2.5.20 has an arbitrary file deletion vulnerability.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %emlog · emlog8 дек. 2025 г.
- CVE-2023-139835Наблюдать
XiaoBingBy TeaCMS upload path traversal
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %teacms project · teacms14 мар. 2023 г.
- CVE-2024-282535Наблюдать
lakernote EasyAdmin saveReportFile path traversal
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %lakernote · easyadmin22 мар. 2024 г.
- CVE-2026-1494734Наблюдать
Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Remote Code Execution via malicious ZIP file
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %frauscher sensortechnik · fds 10220 авг. 2026 г.
- CVE-2021-2672534Наблюдать
Authenticated command path traversal on timezone settings in Guardian/CMC before 20.0.7.4
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %nozominetworks · central management control22 февр. 2021 г.
- CVE-2026-9773034Наблюдать
In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) wi
ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %netgate · pfsense plus5 дней назад