Перейти к содержимому
Noroxi

CWE-27 · 21 записей

Path Traversal: 'dir/../../filename'

CVE этого класса

21 записей

  • CVE-2024-24809
    50В плане

    Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type

    ВысокаяCVSS 8,5Готовый эксплойтEPSS 54 %

    traccar · traccar10 апр. 2024 г.

  • CVE-2024-21896
    39Наблюдать

    The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    nodejs · node.js19 февр. 2024 г.

  • CVE-2025-66518
    35Наблюдать

    Apache Kyuubi: Unauthorized directory access due to missing path normalization

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    apache · kyuubi5 янв. 2026 г.

  • CVE-2023-34125
    34Наблюдать

    Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wi

    СредняяCVSS 6,5Эксплойта нетEPSS 25 %

    sonicwall · analytics12 июл. 2023 г.

  • CVE-2025-10438
    34Наблюдать

    Path Traversal in Yordam BT's Yordam Katalog

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    yordam information technology consulting education and electrical systems industry trade inc. · yordam katalog25 сент. 2025 г.

  • CVE-2021-35027
    31Наблюдать

    A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    zyxel · zywall vpn2s firmware29 сент. 2021 г.

  • CVE-2024-20348
    30Наблюдать

    A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauth

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    cisco · nexus dashboard fabric controller3 апр. 2024 г.

  • CVE-2025-58761
    30Наблюдать

    Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    tautulli · tautulli9 сент. 2025 г.

  • CVE-2026-76344
    30Наблюдать

    Path Traversal through the Search Dispatch REST API in Splunk Enterprise

    ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %

    splunk · splunk19 авг. 2026 г.

  • CVE-2024-43658
    28Наблюдать

    Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    iocharger · iocharger firmware for ac models9 янв. 2025 г.

  • CVE-2023-20129
    26Наблюдать

    Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    cisco · prime infrastructure5 апр. 2023 г.

  • CVE-2023-20127
    26Наблюдать

    Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    cisco · prime infrastructure5 апр. 2023 г.

  • CVE-2025-52237
    26Наблюдать

    An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    sscms · sscms5 авг. 2025 г.

  • CVE-2023-20130
    26Наблюдать

    Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    cisco · prime infrastructure5 апр. 2023 г.

  • CVE-2023-20090
    26Наблюдать

    Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    cisco · telepresence collaboration endpoint15 нояб. 2024 г.

  • CVE-2026-20018
    23Наблюдать

    Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    cisco · cisco secure firewall management center (fmc)4 мар. 2026 г.

  • CVE-2026-17495
    23Наблюдать

    moment vulnerable to Path Traversal via crafted non-string locale name

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    moment · moment15 сент. 2026 г.

  • CVE-2025-58292
    22Наблюдать

    Denial of service (DoS) vulnerability in the office service.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    huawei · harmonyos11 окт. 2025 г.

  • CVE-2023-20131
    21Наблюдать

    Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    cisco · prime infrastructure5 апр. 2023 г.

  • CVE-2024-7458
    20Наблюдать

    elunez eladmin Database Management/Deployment Management upload path traversal

    СредняяCVSS 5,1Эксплойта нетEPSS 1 %

    eladmin · eladmin4 авг. 2024 г.

  • CVE-2024-25828
    19Наблюдать

    cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.

    СредняяCVSS 4,9Эксплойта нетEPSS 1 %

    cmseasy · cmseasy22 февр. 2024 г.

Все классы уязвимостей