İçeriğe atla
Noroxi

CWE-23 · 462 kayıt

Relative Path Traversal

Bu sınıftaki CVE’ler

462 kayıt

  • An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %93

    aviatrix · controller13 Eyl 2021

  • A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %92

    fortinet · fortiweb14 Kas 2025

  • In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible

    YüksekCVSS 7,3KEVSilahlaştırılmışEPSS %100

    jetbrains · teamcity4 Mar 2024

  • Directory Traversal with spring-cloud-config-server

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %96

    vmware · spring cloud config2 Haz 2020

  • CVE-2026-34926
    56Planlayın

    A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table

    OrtaCVSS 6,7KEVSilahlaştırılmışEPSS %1

    trendmicro · apex one21 May 2026

  • CVE-2022-29844
    50Planlayın

    Western Digital My Cloud OS 5 arbitrary file read and write vulnerability via ftp

    KritikCVSS 9,8İstismar yokEPSS %36

    westerndigital · my cloud pr2100 firmware26 Oca 2023

  • CVE-2025-55752
    49Planlayın

    Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled

    YüksekCVSS 7,5Kavram kanıtıEPSS %64

    apache · tomcat27 Eki 2025

  • CVE-2020-5405
    47Planlayın

    Directory Traversal with spring-cloud-config-server

    OrtaCVSS 6,5Kavram kanıtıEPSS %69

    vmware · spring cloud config5 Mar 2020

  • CVE-2023-34990
    46Planlayın

    A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized c

    KritikCVSS 9,8Kavram kanıtıEPSS %25

    fortinet · fortiwlm18 Ara 2024

  • CVE-2020-17518
    45Planlayın

    Apache Flink directory traversal attack: remote file writing through the REST API

    YüksekCVSS 7,5Kavram kanıtıEPSS %51

    apache · flink5 Oca 2021

  • CVE-2022-23854
    44Planlayın

    AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user

    YüksekCVSS 7,5Kavram kanıtıEPSS %46

    aveva · intouch access anywhere23 Ara 2022

  • CVE-2022-2139
    44Planlayın

    The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and execute arbitrary co

    KritikCVSS 9,8İstismar yokEPSS %16

    advantech · iview22 Tem 2022

  • CVE-2024-2053
    43Planlayın

    Artica Proxy Unauthenticated LFI Protection Bypass Vulnerability

    YüksekCVSS 7,5Kavram kanıtıEPSS %45

    articatech · artica proxy20 Mar 2024

  • CVE-2026-23734
    43Planlayın

    XWiki Platform: Path traversal via resources parameter in ssx and jsx endpoints when using leading slash

    KritikCVSS 9,3İstismar yokEPSS %20

    xwiki · xwiki-commons20 May 2026

  • CVE-2021-43555
    42Planlayın

    mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vul

    YüksekCVSS 7,8İstismar yokEPSS %38

    myscada · mydesigner19 Kas 2021

  • CVE-2025-34510
    42Planlayın

    Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip

    YüksekCVSS 8,8SilahlaştırılmışEPSS %24

    sitecore · experience commerce17 Haz 2025

  • CVE-2020-8271
    42Planlayın

    Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8

    KritikCVSS 9,8İstismar yokEPSS %11

    citrix · sd-wan15 Kas 2020

  • CVE-2024-24578
    42Planlayın

    RaspberryMatic Unauthenticated Remote Code Execution vulnerability through HMServer File Upload

    KritikCVSS 9,8SilahlaştırılmışEPSS %9

    raspberrymatic · raspberrymatic18 Mar 2024

  • CVE-2020-25176
    41Planlayın

    Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal

    KritikCVSS 9,8İstismar yokEPSS %6

    schneider-electric · easergy t300 firmware18 Mar 2022

  • CVE-2023-6825
    41Planlayın

    File Manager And File Manager Pro (Multiple Versions) - Directory Traversal

    KritikCVSS 9,9Kavram kanıtıEPSS %6

    mndpsingh287 · file manager13 Mar 2024

  • CVE-2025-47445
    41Planlayın

    WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    themewinter · eventin14 May 2025

  • CVE-2012-6069
    41Planlayın

    3S CoDeSys Relative Path Traversal

    KritikCVSS 10,0İstismar yokEPSS %3

    3s-software · codesys runtime system21 Oca 2013

  • CVE-2020-10619
    40Planlayın

    An attacker could use a specially crafted URL to delete files outside the WebAccess/NMS's (versions prior to 3.0.2) control.

    KritikCVSS 9,1İstismar yokEPSS %14

    advantech · webaccess\/nms9 Nis 2020

  • CVE-2020-12006
    40Planlayın

    Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0.

    KritikCVSS 9,8İstismar yokEPSS %4

    advantech · webaccess8 May 2020

  • CVE-2020-27304
    40Planlayın

    The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-ba

    KritikCVSS 9,8İstismar yokEPSS %3

    civetweb project · civetweb21 Eki 2021

Tüm zafiyet sınıfları