CWE-24
107 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-24page 3 of 3
- CVE-2026-21857MEDIUMCVSS 6.5EG 6.52026-01-07
REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions can read arbitrary files within the webroot via path traversal in the Backup addon's file export functionality. The Backu…
- CVE-2026-22810HIGHCVSS 8.2EG 8.22026-05-18
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The …
- CVE-2026-33431MEDIUMCVSS 6.5EG 6.52026-04-20
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POST /config/<service>/show API endpoint accepts a configver parameter that is directly appended to a base directory path …
- CVE-2026-39813CRITICALCVSS 9.8EG 9.82026-04-14
A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>
- CVE-2026-40318HIGHCVSS 8.5EG 8.52026-04-16
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path bound…
- CVE-2026-41082HIGHCVSS 7.3EG 7.32026-04-16
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
- CVE-2026-49103CRITICALCVSS 9.4EG 9.42026-05-27
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.
Map vulnerabilities like CWE-24 to your infrastructure
EchelonGraph correlates every CVE — across CWE-24 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →