CWE-36
119 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-36page 1 of 3
- CVE-2018-20250HIGHCVSS 7.8EG 9.0⚠ KEV2019-02-05
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extr…
- CVE-2021-1296HIGHCVSS 7.5EG 7.52021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrit…
- CVE-2021-1297HIGHCVSS 7.5EG 7.52021-02-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W VPN Routers could allow an unauthenticated, remote attacker to conduct directory traversal attacks and overwrit…
- CVE-2021-1617MEDIUMCVSS 6.5EG 6.52021-07-22
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnera…
- CVE-2021-1618MEDIUMCVSS 6.5EG 7.22021-07-22
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnera…
- CVE-2021-21586HIGHCVSS 8.1EG 8.12021-07-15
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.
- CVE-2021-30173MEDIUMCVSS 6.5EG 6.52021-05-07
Local File Inclusion vulnerability of the omni-directional communication system allows remote authenticated attacker inject absolute path into Url parameter and access arbitrary file.
- CVE-2021-32506MEDIUMCVSS 6.5EG 6.52021-07-07
Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of QSA…
- CVE-2021-32507MEDIUMCVSS 6.5EG 6.52021-07-07
Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers download arbitrary files via the Url path parameter. The referred vulnerability has been solved with the updated version of…
- CVE-2021-34711MEDIUMCVSS 5.5EG 5.52021-10-06
A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any file on the device file system. This vulnerability is due to insufficient input validation. An attacker could exploit th…
- CVE-2022-1554HIGHCVSS 7.5EG 7.52022-05-03
Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
- CVE-2022-20791MEDIUMCVSS 6.5EG 6.52022-07-06
A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Prese…
- CVE-2022-20958HIGHCVSS 8.3EG 8.82022-11-04
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerabi…
- CVE-2022-24877CRITICALCVSS 9.9EG 9.92022-05-06
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem …
- CVE-2023-1176LOWCVSS 3.3EG 3.32023-03-24
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.2.2.
- CVE-2023-2101MEDIUMCVSS 4.3EG 6.52023-04-15
A vulnerability, which was classified as problematic, has been found in moxi624 Mogu Blog v2 up to 5.2. This issue affects the function uploadPictureByUrl of the file /mogu-picture/file/uploadPicsByUrl. The manipulation of the argument url…
- CVE-2023-2765MEDIUMCVSS 4.3EG 4.32023-05-17
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path tr…
- CVE-2023-30970MEDIUMCVSS 6.5EG 6.52024-01-29
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on the file system.
- CVE-2023-32054HIGHCVSS 7.3EG 7.32023-07-11
Volume Shadow Copy Elevation of Privilege Vulnerability
- CVE-2023-33871HIGHCVSS 7.5EG 7.52023-07-18
Iagona ScrutisWeb versions 2.1.37 and prior are vulnerable to a directory traversal vulnerability that could allow an unauthenticated user to directly access any file outside the webroot.
- CVE-2023-34135MEDIUMCVSS 6.5EG 6.52023-07-13
Path Traversal vulnerability in SonicWall GMS and Analytics allows a remote authenticated attacker to read arbitrary files from the underlying file system via web service. This issue affects GMS: 9.3.2-SP1 and earlier versions; Analytics: …
- CVE-2023-36786HIGHCVSS 7.2EG 7.22023-10-10
Skype for Business Remote Code Execution Vulnerability
- CVE-2023-3765CRITICALCVSS 10.0EG 10.02023-07-19
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
- CVE-2023-40597HIGHCVSS 7.8EG 7.82023-08-30
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
- CVE-2023-4172MEDIUMCVSS 4.3EG 4.32023-08-05
A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\FileHandler.ashx. The manipulation of t…
- CVE-2023-41830MEDIUMCVSS 6.5EG 6.52024-05-03
An improper absolute path traversal vulnerability was reported for the Ready For application allowing a local application access to files without authorization.
- CVE-2023-5022MEDIUMCVSS 5.5EG 5.52023-09-17
A vulnerability has been found in DedeCMS up to 5.7.100 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_templets_post.php. The manipulation of the argument activepat…
- CVE-2023-50955LOWCVSS 2.4EG 2.42024-02-21
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the web server installation which could aid in further attacks against the system. IBM X-Force ID: 275777.
- CVE-2023-5115MEDIUMCVSS 6.3EG 6.32023-12-18
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extr…
- CVE-2023-5390MEDIUMCVSS 5.3EG 5.32024-01-31
An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion ControlEdge VirtualUOC and ControlEdge UOC. This exploit could be used to read files from the controller that may expose limi…
- CVE-2024-10047MEDIUMCVSS 5.3EG 5.32025-03-20
parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.
- CVE-2024-10651MEDIUMCVSS 4.9EG 4.92024-11-01
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrator privileges to exploit this vulnerability to read arbitrary system fi…
- CVE-2024-10811CRITICALCVSS 9.8EG 9.82025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-10831CRITICALCVSS 9.1EG 9.12025-03-20
In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises …
- CVE-2024-10833CRITICALCVSS 9.1EG 9.12025-03-20
eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary…
- CVE-2024-11978HIGHCVSS 7.5EG 7.52024-11-29
DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files.
- CVE-2024-12375MEDIUMCVSS 6.5EG 6.52025-03-20
A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request …
- CVE-2024-12643HIGHCVSS 8.1EG 8.12024-12-16
The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs,…
- CVE-2024-12644HIGHCVSS 7.1EG 7.12024-12-16
The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauth…
- CVE-2024-12646HIGHCVSS 8.1EG 8.12024-12-16
The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs…
- CVE-2024-13159CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-13160CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-13161CRITICALCVSS 9.8EG 9.8⚠ KEV2025-01-14
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
- CVE-2024-13945MEDIUMCVSS 6.0EG 6.02025-05-23
Stored Absolute Path Traversal vulnerabilities in ASPECT could expose sensitive data if administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.…
- CVE-2024-1703LOWCVSS 3.5EG 3.52024-02-21
A vulnerability was found in ZhongBangKeJi CRMEB 5.2.2. It has been classified as problematic. This affects the function openfile of the file /adminapi/system/file/openfile. The manipulation leads to absolute path traversal. The exploit ha…
- CVE-2024-20379MEDIUMCVSS 6.5EG 6.52024-10-23
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to read arbitrary files from the …
- CVE-2024-20401CRITICALCVSS 9.8EG 9.82024-07-17
A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to overwrite arbitrary files on the underlying operating system. This vulnerability is …
- CVE-2024-21323HIGHCVSS 8.8EG 8.82024-04-09
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2024-2362CRITICALCVSS 9.1EG 9.12024-06-06
A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this vulnerability to delete a…
- CVE-2024-2548HIGHCVSS 7.5EG 7.52024-06-06
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files. Due to inadequate vali…
Map vulnerabilities like CWE-36 to your infrastructure
EchelonGraph correlates every CVE — across CWE-36 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →