CWE-23: CWE-23

146
Total CVEs
26
Critical
76
High
7.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
12
2025
69
2024
34
2023
11
2022
6

Top Affected Vendors

1 Fortinet 9
2 Microsoft 5
3 Jetbrains 5
4 Trcore 4
5 Dell 3
6 Qnap 3
7 Apache 3
8 Rockwellautomation 2
9 Flutter 2
10 Ibm 2

All CWE-23 CVEs (146)

CVE-2024-45731
8.0

This vulnerability allows low-privileged Splunk users without admin or power roles to write files to the Windows system root directory (typically Syst...

Oct 14, 2024
CVE-2024-43399
8.0

This vulnerability in MobSF allows attackers to bypass Zip Slip protections during static library analysis, enabling arbitrary file extraction to any ...

Aug 19, 2024
CVE-2025-10203
7.8

A relative path traversal vulnerability in Digilent WaveForms allows attackers to execute arbitrary code by tricking users into opening malicious .DWF...

Sep 15, 2025
CVE-2023-35359
7.8

This Windows kernel vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges, potentially taking full control o...

Aug 8, 2023
CVE-2023-34394
7.8

Keysight Geolocation Server v2.4.2 and earlier contain a path traversal vulnerability that allows attackers to upload malicious files or delete arbitr...

Jul 19, 2023
CVE-2022-42470
7.8

This CVE describes a relative path traversal vulnerability in Fortinet FortiClient for Windows that allows attackers to execute arbitrary code or comm...

Apr 11, 2023
CVE-2023-23379
7.8

CVE-2023-23379 is an elevation of privilege vulnerability in Microsoft Defender for IoT that allows authenticated attackers to execute arbitrary code ...

Feb 14, 2023
CVE-2024-22421
7.6

This CVE describes a redirect vulnerability in JupyterLab where clicking a malicious link can expose Authorization and XSRFToken tokens to third parti...

Jan 19, 2024
CVE-2020-25150
7.6

This vulnerability allows attackers with service user privileges to perform relative path traversal attacks in B. Braun medical devices. By uploading ...

Apr 14, 2022
CVE-2026-25575
7.5

CVE-2026-25575 is a path traversal vulnerability in NavigaTUM's propose_edits endpoint that allows unauthenticated attackers to overwrite files in wri...

Feb 4, 2026
CVE-2026-25121
7.5

A path traversal vulnerability in apko's dirFS filesystem abstraction allows attackers to create directories or symlinks outside the intended installa...

Feb 4, 2026
CVE-2026-1022
7.5

The Gotac Statistics Database System contains an arbitrary file read vulnerability that allows unauthenticated remote attackers to download any system...

Jan 16, 2026
CVE-2025-67366
7.5

CVE-2025-67366 is a critical path traversal vulnerability in @sylphxltd/filesystem-mcp v0.5.8 that allows attackers to bypass directory restrictions u...

Jan 7, 2026
CVE-2025-15225
7.5

WMPro software developed by Sunnet contains an arbitrary file read vulnerability due to relative path traversal. Unauthenticated remote attackers can ...

Dec 29, 2025
CVE-2025-57403
7.5

Cola Dnslog v1.3.2 has a directory traversal vulnerability in TXT record processing that allows attackers to read arbitrary files on the server. This ...

Dec 26, 2025
CVE-2025-15015
7.5

CVE-2025-15015 is an arbitrary file read vulnerability in Ragic's Enterprise Cloud Database that allows unauthenticated remote attackers to download a...

Dec 22, 2025
CVE-2025-12097
7.5

A relative path traversal vulnerability in NI System Web Server allows attackers to read arbitrary files by sending specially crafted requests. This a...

Dec 4, 2025
CVE-2025-13161
7.5

CVE-2025-13161 is an arbitrary file read vulnerability in IQ-Support software that allows unauthenticated remote attackers to download any system file...

Nov 14, 2025
CVE-2025-58464
7.5

A relative path traversal vulnerability in QuMagie allows remote attackers to read arbitrary files on the system. This affects all QuMagie installatio...

Nov 7, 2025
CVE-2025-55752
7.5

A path traversal vulnerability in Apache Tomcat allows attackers to bypass security constraints protecting sensitive directories like /WEB-INF/ and /M...

Oct 27, 2025
CVE-2025-58429
7.5

An unauthenticated remote attacker can exploit a relative path traversal vulnerability in Productivity Suite software to delete arbitrary files on the...

Oct 23, 2025
CVE-2025-58078
7.5

An unauthenticated remote attacker can exploit a relative path traversal vulnerability in Productivity Suite software to write arbitrary files to the ...

Oct 23, 2025
CVE-2025-11898
7.5

Agentflow software by Flowring contains an unauthenticated arbitrary file reading vulnerability via relative path traversal. Remote attackers can expl...

Oct 17, 2025
CVE-2025-9639
7.5

CVE-2025-9639 is an arbitrary file reading vulnerability in Ai3's QbiCRMGateway software that allows unauthenticated remote attackers to download any ...

Aug 29, 2025
CVE-2025-48957
7.5

A path traversal vulnerability in AstrBot versions 3.4.4 through 3.5.12 allows attackers to access sensitive files like API keys and passwords. This a...

Jun 2, 2025
CVE-2025-29789
7.5

OpenEMR versions before 7.3.0 contain a directory traversal vulnerability in the Load Code feature that allows attackers to read arbitrary files on th...

Mar 25, 2025
CVE-2025-27553
7.5

This CVE describes a path traversal vulnerability in Apache Commons VFS where encoded '..' sequences (%2E%2E) bypass the NameScope.DESCENDENT validati...

Mar 23, 2025
CVE-2024-9363
7.5

An unauthenticated attacker can delete critical files like polyaxon.sock within Polyaxon containers, causing API containers to exit and leading to den...

Mar 20, 2025
CVE-2025-2056
7.5

The WP Ghost (Hide My WP Ghost) plugin for WordPress has a path traversal vulnerability in the showFile function, allowing unauthenticated attackers t...

Mar 14, 2025
CVE-2025-27610
7.5

This vulnerability in Rack's static file serving component allows attackers to bypass directory restrictions and access any file under the configured ...

Mar 10, 2025
CVE-2024-11309
7.5

CVE-2024-11309 is a path traversal vulnerability in DVC from TRCore that allows unauthenticated remote attackers to read arbitrary system files. This ...

Nov 18, 2024
CVE-2024-9922
7.5

CVE-2024-9922 is a path traversal vulnerability in Team+ software from TEAMPLUS TECHNOLOGY that allows unauthenticated remote attackers to read arbitr...

Oct 14, 2024
CVE-2024-7693
7.5

CVE-2024-7693 is a relative path traversal vulnerability in Raiden MAILD Remote Management System that allows unauthenticated remote attackers to read...

Aug 12, 2024
CVE-2024-6433
7.5

This vulnerability allows attackers to read arbitrary files on the system by providing a crafted path parameter to an application's file zipping funct...

Jul 10, 2024
CVE-2024-5547
7.5

A directory traversal vulnerability in the stitionai/devika repository allows attackers to download arbitrary PDF files from the system by manipulatin...

Jun 27, 2024
CVE-2024-0335
7.5

This vulnerability in ABB's S+ Control API component allows attackers to exploit path traversal (CWE-23) through the VPNI feature. It affects multiple...

Apr 3, 2024
CVE-2024-2053
7.5

CVE-2024-2053 is a critical vulnerability in Artica Proxy's administrative web application that allows unauthenticated attackers to execute arbitrary ...

Mar 21, 2024
CVE-2023-31036
7.5

NVIDIA Triton Inference Server has a path traversal vulnerability when launched with the --model-control explicit option. Attackers can exploit this v...

Jan 12, 2024
CVE-2023-46119
7.5

Parse Server crashes when processing file uploads without file extensions, causing denial of service. This affects all Parse Server deployments runnin...

Oct 25, 2023
CVE-2023-3512
7.5

This vulnerability allows attackers to download arbitrary files from affected systems using relative path traversal in the 'Download file' parameter. ...

Oct 4, 2023
CVE-2023-4914
7.5

This vulnerability allows attackers to perform relative path traversal attacks in Cecil static site generator. By manipulating file paths, attackers c...

Sep 12, 2023
CVE-2023-2913
7.5

A path traversal vulnerability in Rockwell Automation ThinManager ThinServer allows remote attackers to read arbitrary files on the server's file syst...

Jul 18, 2023
CVE-2022-2120
7.5

This vulnerability in OFFIS DCMTK's service class user (SCU) allows attackers to write DICOM files to arbitrary directories via relative path traversa...

Jun 24, 2022
CVE-2021-20040
7.5

A relative path traversal vulnerability in SonicWall SMA appliances allows unauthenticated remote attackers to upload arbitrary files as a low-privile...

Dec 8, 2021
CVE-2021-29101
7.5

This vulnerability allows unauthenticated remote attackers to read arbitrary files on ArcGIS GeoEvent Server systems by exploiting a directory travers...

May 5, 2021
CVE-2024-22415
7.3

CVE-2024-22415 is a path traversal vulnerability in jupyter-lsp that allows attackers to access and modify files outside the Jupyter root directory wh...

Jan 18, 2024
CVE-2021-34605
7.3

This zip slip vulnerability in XINJE XD/E Series PLC Program Tool allows attackers to write arbitrary files when opening malicious project files or re...

May 11, 2022
CVE-2021-43555
7.3

CVE-2021-43555 is a path traversal vulnerability in mySCADA myDESIGNER that allows attackers to write arbitrary files to the file system via malicious...

Nov 19, 2021
CVE-2025-26349
7.2

This vulnerability allows authenticated remote attackers to overwrite arbitrary files on Q-Free MaxTime systems by exploiting a relative path traversa...

Feb 12, 2025
CVE-2025-23360
7.1

CVE-2025-23360 is a relative path traversal vulnerability in NVIDIA Nemo Framework that allows authenticated users to write arbitrary files to uninten...

Mar 11, 2025

About CWE-23 (CWE-23)

Our database tracks 146 CVEs classified as CWE-23, with 26 rated critical and 76 rated high severity. The average CVSS score for CWE-23 vulnerabilities is 7.4.

External reference: View CWE-23 on MITRE CWE →

Monitor CWE-23 Vulnerabilities

Get alerted when new CWE-23 CVEs affect your infrastructure.

Start Monitoring Free