CWE-27 · 21 записей
Path Traversal: 'dir/../../filename'
CVE этого класса
21 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
50В плане | CVE-2024-24809Готовый эксплойт | Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Typetraccar · traccar · CWE-27 | Высокая8,5 | — | 54,4 % | 10 апр. 2024 г. |
39Наблюдать | CVE-2024-21896Эксплойта нет | The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user.nodejs · node.js · CWE-27 | Критическая9,8 | — | 1,3 % | 19 февр. 2024 г. |
35Наблюдать | CVE-2025-66518Эксплойта нет | Apache Kyuubi: Unauthorized directory access due to missing path normalizationapache · kyuubi · CWE-27 | Высокая8,8 | — | 1,1 % | 5 янв. 2026 г. |
34Наблюдать | CVE-2023-34125Эксплойта нет | Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wisonicwall · analytics · CWE-27 | Средняя6,5 | — | 25,4 % | 12 июл. 2023 г. |
34Наблюдать | CVE-2025-10438Эксплойта нет | Path Traversal in Yordam BT's Yordam Katalogyordam information technology consulting education and electrical systems industry trade inc. · yordam katalog · CWE-27 | Высокая8,6 | — | 0,4 % | 25 сент. 2025 г. |
31Наблюдать | CVE-2021-35027Эксплойта нет | A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access zyxel · zywall vpn2s firmware · CWE-27 | Высокая7,5 | — | 2,0 % | 29 сент. 2021 г. |
30Наблюдать | CVE-2024-20348Эксплойта нет | A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthcisco · nexus dashboard fabric controller · CWE-27 | Высокая7,5 | — | 0,8 % | 3 апр. 2024 г. |
30Наблюдать | CVE-2025-58761Эксплойта нет | Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`tautulli · tautulli · CWE-27 | Высокая7,5 | — | 0,7 % | 9 сент. 2025 г. |
30Наблюдать | CVE-2026-76344Эксплойта нет | Path Traversal through the Search Dispatch REST API in Splunk Enterprisesplunk · splunk · CWE-27 | Высокая7,7 | — | 0,4 % | 19 авг. 2026 г. |
28Наблюдать | CVE-2024-43658Эксплойта нет | Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.iocharger · iocharger firmware for ac models · CWE-27 | Высокая7,2 | — | 0,5 % | 9 янв. 2025 г. |
26Наблюдать | CVE-2023-20129Эксплойта нет | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Средняя6,5 | — | 0,9 % | 5 апр. 2023 г. |
26Наблюдать | CVE-2023-20127Эксплойта нет | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Средняя6,5 | — | 0,9 % | 5 апр. 2023 г. |
26Наблюдать | CVE-2025-52237Эксплойта нет | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.sscms · sscms · CWE-27 | Средняя6,5 | — | 0,5 % | 5 авг. 2025 г. |
26Наблюдать | CVE-2023-20130Эксплойта нет | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Средняя6,5 | — | 0,4 % | 5 апр. 2023 г. |
26Наблюдать | CVE-2023-20090Эксплойта нет | Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerabilitycisco · telepresence collaboration endpoint · CWE-27 | Средняя6,7 | — | 0,2 % | 15 нояб. 2024 г. |
23Наблюдать | CVE-2026-20018Эксплойта нет | Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerabilitycisco · cisco secure firewall management center (fmc) · CWE-27 | Средняя5,9 | — | 0,4 % | 4 мар. 2026 г. |
23Наблюдать | CVE-2026-17495Эксплойта нет | moment vulnerable to Path Traversal via crafted non-string locale namemoment · moment · CWE-27 | Средняя5,9 | — | 0,4 % | 15 сент. 2026 г. |
22Наблюдать | CVE-2025-58292Эксплойта нет | Denial of service (DoS) vulnerability in the office service.huawei · harmonyos · CWE-27 | Средняя5,5 | — | 0,1 % | 11 окт. 2025 г. |
21Наблюдать | CVE-2023-20131Эксплойта нет | Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilitiescisco · prime infrastructure · CWE-27 | Средняя5,4 | — | 0,6 % | 5 апр. 2023 г. |
20Наблюдать | CVE-2024-7458Эксплойта нет | elunez eladmin Database Management/Deployment Management upload path traversaleladmin · eladmin · CWE-27 | Средняя5,1 | — | 0,8 % | 4 авг. 2024 г. |
19Наблюдать | CVE-2024-25828Эксплойта нет | cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.cmseasy · cmseasy · CWE-27 | Средняя4,9 | — | 0,6 % | 22 февр. 2024 г. |
- CVE-2024-2480950В плане
Traccar vulnerable to Path Traversal: 'dir/../../filename' and Unrestricted Upload of File with Dangerous Type
ВысокаяCVSS 8,5Готовый эксплойтEPSS 54 %traccar · traccar10 апр. 2024 г.
- CVE-2024-2189639Наблюдать
The permission model protects itself against path traversal attacks by calling path.resolve() on any paths given by the user.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %nodejs · node.js19 февр. 2024 г.
- CVE-2025-6651835Наблюдать
Apache Kyuubi: Unauthorized directory access due to missing path normalization
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %apache · kyuubi5 янв. 2026 г.
- CVE-2023-3412534Наблюдать
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem wi
СредняяCVSS 6,5Эксплойта нетEPSS 25 %sonicwall · analytics12 июл. 2023 г.
- CVE-2025-1043834Наблюдать
Path Traversal in Yordam BT's Yordam Katalog
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %yordam information technology consulting education and electrical systems industry trade inc. · yordam katalog25 сент. 2025 г.
- CVE-2021-3502731Наблюдать
A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote attacker to gain access
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %zyxel · zywall vpn2s firmware29 сент. 2021 г.
- CVE-2024-2034830Наблюдать
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauth
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cisco · nexus dashboard fabric controller3 апр. 2024 г.
- CVE-2025-5876130Наблюдать
Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy`
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %tautulli · tautulli9 сент. 2025 г.
- CVE-2026-7634430Наблюдать
Path Traversal through the Search Dispatch REST API in Splunk Enterprise
ВысокаяCVSS 7,7Эксплойта нетEPSS 0 %splunk · splunk19 авг. 2026 г.
- CVE-2024-4365828Наблюдать
Using the <redacted> action or <redacted>.sh script, arbitrary files and directories can be deleted using directory traversal.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %iocharger · iocharger firmware for ac models9 янв. 2025 г.
- CVE-2023-2012926Наблюдать
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · prime infrastructure5 апр. 2023 г.
- CVE-2023-2012726Наблюдать
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cisco · prime infrastructure5 апр. 2023 г.
- CVE-2025-5223726Наблюдать
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sscms · sscms5 авг. 2025 г.
- CVE-2023-2013026Наблюдать
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
СредняяCVSS 6,5Эксплойта нетEPSS 0 %cisco · prime infrastructure5 апр. 2023 г.
- CVE-2023-2009026Наблюдать
Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability
СредняяCVSS 6,7Эксплойта нетEPSS 0 %cisco · telepresence collaboration endpoint15 нояб. 2024 г.
- CVE-2026-2001823Наблюдать
Cisco Firepower Management Center Software and Firepower Threat Defense Path Traversal Vulnerability
СредняяCVSS 5,9Эксплойта нетEPSS 0 %cisco · cisco secure firewall management center (fmc)4 мар. 2026 г.
- CVE-2026-1749523Наблюдать
moment vulnerable to Path Traversal via crafted non-string locale name
СредняяCVSS 5,9Эксплойта нетEPSS 0 %moment · moment15 сент. 2026 г.
- CVE-2025-5829222Наблюдать
Denial of service (DoS) vulnerability in the office service.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %huawei · harmonyos11 окт. 2025 г.
- CVE-2023-2013121Наблюдать
Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Vulnerabilities
СредняяCVSS 5,4Эксплойта нетEPSS 1 %cisco · prime infrastructure5 апр. 2023 г.
- CVE-2024-745820Наблюдать
elunez eladmin Database Management/Deployment Management upload path traversal
СредняяCVSS 5,1Эксплойта нетEPSS 1 %eladmin · eladmin4 авг. 2024 г.
- CVE-2024-2582819Наблюдать
cmseasy V7.7.7.9 has an arbitrary file deletion vulnerability in lib/admin/template_admin.php.
СредняяCVSS 4,9Эксплойта нетEPSS 1 %cmseasy · cmseasy22 февр. 2024 г.