CWE-31
11 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-31page 1 of 1
- CVE-2019-6268HIGHCVSS 7.5EG 7.52024-03-08
RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow.
- CVE-2023-35860MEDIUMCVSS 5.3EG 5.32024-06-13
A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listing.php or rss.php.
- CVE-2024-2044CRITICALCVSS 9.9EG 9.92024-03-07
pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle object…
- CVE-2024-22723MEDIUMCVSS 4.9EG 4.92024-02-28
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attacker (in this case, an administrator) can navigate beyond the intended directory (the 'media/' directory) to access sensi…
- CVE-2024-24998HIGHCVSS 8.8EG 8.82024-04-19
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
- CVE-2024-25840HIGHCVSS 7.5EG 7.52024-02-27
In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information without restriction by performing a path traversal attack.
- CVE-2024-28088HIGHCVSS 8.1EG 8.12024-03-04
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended behavior of loading configurations only from the hwchase17/lan…
- CVE-2024-35429MEDIUMCVSS 6.5EG 6.52024-05-30
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord.
- CVE-2024-35431HIGHCVSS 7.5EG 7.52024-05-30
ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indicated other versions are also vulnerable including up to 6.4…
- CVE-2024-36857HIGHCVSS 7.5EG 7.52024-06-04
Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.
- CVE-2024-41376HIGHCVSS 8.8EG 8.82024-08-05
dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php.
Map vulnerabilities like CWE-31 to your infrastructure
EchelonGraph correlates every CVE — across CWE-31 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →