CWE-36 · 134 записей
Absolute Path Traversal
CVE этого класса
134 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
92Срочно | CVE-2024-48248Готовый эксплойт | NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lnakivo · backup \& replication director · CWE-36 | Высокая8,6 | KEV | 94,4 % | 4 мар. 2025 г. |
90Срочно | CVE-2024-13159Готовый эксплойт | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Высокая7,5 | KEV | 100,0 % | 14 янв. 2025 г. |
90Срочно | CVE-2018-20250Готовый эксплойт | In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (inrarlab · winrar · CWE-36 | Высокая7,8 | KEV | 96,0 % | 5 февр. 2019 г. |
87Срочно | CVE-2024-13160Готовый эксплойт | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Высокая7,5 | KEV | 91,2 % | 14 янв. 2025 г. |
87Срочно | CVE-2024-13161Готовый эксплойт | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Высокая7,5 | KEV | 90,1 % | 14 янв. 2025 г. |
60На этой неделе | CVE-2023-3765Proof of concept | Absolute Path Traversal in mlflow/mlflowlfprojects · mlflow · CWE-36 | Критическая10,0 | — | 67,6 % | 18 июл. 2023 г. |
47В плане | CVE-2025-34392Эксплойта нет | Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCEbarracuda · rmm · CWE-36 | Критическая10,0 | — | 24,7 % | 10 дек. 2025 г. |
44В плане | CVE-2025-0851Proof of concept | Path traversal issue in Deep Java Libraryaws · deepjavalibrary · CWE-36 | Критическая9,3 | — | 23,3 % | 29 янв. 2025 г. |
40В плане | CVE-2025-57790Готовый эксплойт | Path Traversal Vulnerabilitycommvault · commvault · CWE-36 | Высокая8,7 | — | 19,4 % | 20 авг. 2025 г. |
40В плане | CVE-2024-20401Эксплойта нет | A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote cisco · secure email gateway · CWE-36 | Критическая9,8 | — | 2,3 % | 17 июл. 2024 г. |
40В плане | CVE-2026-57211Эксплойта нет | RabbitMQ: UNC SSRF affecting the management UI on Windowsbroadcom · rabbitmq server · CWE-36 | Критическая10,0 | — | 0,6 % | 10 июл. 2026 г. |
39Наблюдать | CVE-2024-9924Эксплойта нет | Hgiga OAKlouds - Arbitrary File Read And Deletehgiga · oaklouds · CWE-36 | Критическая9,8 | — | 0,8 % | 14 окт. 2024 г. |
39Наблюдать | CVE-2026-68487Эксплойта нет | Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.webpros · plesk · CWE-36 | Критическая9,9 | — | 0,6 % | 10 сент. 2026 г. |
37Наблюдать | CVE-2024-51549Эксплойта нет | Absolute Path Traversalabb · aspect-ent-12 firmware · CWE-36 | Критическая9,3 | — | 0,5 % | 5 дек. 2024 г. |
36Наблюдать | CVE-2024-29053Эксплойта нет | Microsoft Defender for IoT Remote Code Execution Vulnerabilitymicrosoft · defender for iot · CWE-36 | Высокая8,8 | — | 3,2 % | 9 апр. 2024 г. |
36Наблюдать | CVE-2024-21323Эксплойта нет | Microsoft Defender for IoT Remote Code Execution Vulnerabilitymicrosoft · defender for iot · CWE-36 | Высокая8,8 | — | 3,2 % | 9 апр. 2024 г. |
36Наблюдать | CVE-2024-47883Эксплойта нет | Butterfly has path/URL confusion in resource handling leading to multiple weaknessesopenrefine · butterfly · CWE-36 | Критическая9,1 | — | 1,6 % | 24 окт. 2024 г. |
36Наблюдать | CVE-2024-2362Эксплойта нет | Path Traversal in parisneo/lollms-webuilollms · lollms web ui · CWE-36 | Критическая9,1 | — | 1,2 % | 6 июн. 2024 г. |
36Наблюдать | CVE-2024-10833Эксплойта нет | Arbitrary File Write in eosphoros-ai/db-gptdbgpt · db-gpt · CWE-36 | Критическая9,1 | — | 0,8 % | 20 мар. 2025 г. |
36Наблюдать | CVE-2024-10831Эксплойта нет | Arbitrary File Write through Absolute Path Traversal in eosphoros-ai/db-gptdbgpt · db-gpt · CWE-36 | Критическая9,1 | — | 0,8 % | 20 мар. 2025 г. |
36Наблюдать | CVE-2026-47606Эксплойта нет | NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal.nvidia · triton inference server · CWE-36 | Критическая9,1 | — | 0,7 % | 18 авг. 2026 г. |
35Наблюдать | CVE-2022-20958Эксплойта нет | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attaccisco · broadworks commpilot application · CWE-36 | Высокая8,8 | — | 1,0 % | 4 нояб. 2022 г. |
35Наблюдать | CVE-2026-89009Эксплойта нет | WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_serverwavlink technology · wn535m1 · CWE-36 | Высокая8,8 | — | 1,0 % | 11 сент. 2026 г. |
35Наблюдать | CVE-2024-8501Эксплойта нет | Arbitrary File Download in modelscope/agentscopemodelscope · agentscope · CWE-36 | Высокая8,8 | — | 1,0 % | 20 мар. 2025 г. |
35Наблюдать | CVE-2024-45291Эксплойта нет | Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheetphpoffice · phpspreadsheet · CWE-36 | Высокая8,8 | — | 0,9 % | 7 окт. 2024 г. |
- CVE-2024-4824892Срочно
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may l
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 94 %nakivo · backup \& replication director4 мар. 2025 г.
- CVE-2024-1315990Срочно
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager14 янв. 2025 г.
- CVE-2018-2025090Срочно
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 96 %rarlab · winrar5 февр. 2019 г.
- CVE-2024-1316087Срочно
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 91 %ivanti · endpoint manager14 янв. 2025 г.
- CVE-2024-1316187Срочно
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 90 %ivanti · endpoint manager14 янв. 2025 г.
- CVE-2023-376560На этой неделе
Absolute Path Traversal in mlflow/mlflow
КритическаяCVSS 10,0Proof of conceptEPSS 68 %lfprojects · mlflow18 июл. 2023 г.
- CVE-2025-3439247В плане
Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE
КритическаяCVSS 10,0Эксплойта нетEPSS 25 %barracuda · rmm10 дек. 2025 г.
- CVE-2025-085144В плане
Path traversal issue in Deep Java Library
КритическаяCVSS 9,3Proof of conceptEPSS 23 %aws · deepjavalibrary29 янв. 2025 г.
- CVE-2025-5779040В плане
Path Traversal Vulnerability
ВысокаяCVSS 8,7Готовый эксплойтEPSS 19 %commvault · commvault20 авг. 2025 г.
- CVE-2024-2040140В плане
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cisco · secure email gateway17 июл. 2024 г.
- CVE-2026-5721140В плане
RabbitMQ: UNC SSRF affecting the management UI on Windows
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %broadcom · rabbitmq server10 июл. 2026 г.
- CVE-2024-992439Наблюдать
Hgiga OAKlouds - Arbitrary File Read And Delete
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %hgiga · oaklouds14 окт. 2024 г.
- CVE-2026-6848739Наблюдать
Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %webpros · plesk10 сент. 2026 г.
- CVE-2024-5154937Наблюдать
Absolute Path Traversal
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %abb · aspect-ent-12 firmware5 дек. 2024 г.
- CVE-2024-2905336Наблюдать
Microsoft Defender for IoT Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %microsoft · defender for iot9 апр. 2024 г.
- CVE-2024-2132336Наблюдать
Microsoft Defender for IoT Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %microsoft · defender for iot9 апр. 2024 г.
- CVE-2024-4788336Наблюдать
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %openrefine · butterfly24 окт. 2024 г.
- CVE-2024-236236Наблюдать
Path Traversal in parisneo/lollms-webui
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %lollms · lollms web ui6 июн. 2024 г.
- CVE-2024-1083336Наблюдать
Arbitrary File Write in eosphoros-ai/db-gpt
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %dbgpt · db-gpt20 мар. 2025 г.
- CVE-2024-1083136Наблюдать
Arbitrary File Write through Absolute Path Traversal in eosphoros-ai/db-gpt
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %dbgpt · db-gpt20 мар. 2025 г.
- CVE-2026-4760636Наблюдать
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %nvidia · triton inference server18 авг. 2026 г.
- CVE-2022-2095835Наблюдать
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attac
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cisco · broadworks commpilot application4 нояб. 2022 г.
- CVE-2026-8900935Наблюдать
WAVLINK WN535M1/WN535M3 Unauthenticated Arbitrary File Write via sync_server
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wavlink technology · wn535m111 сент. 2026 г.
- CVE-2024-850135Наблюдать
Arbitrary File Download in modelscope/agentscope
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %modelscope · agentscope20 мар. 2025 г.
- CVE-2024-4529135Наблюдать
Path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled in PHPSpreadsheet
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phpoffice · phpspreadsheet7 окт. 2024 г.