CWE-23: CWE-23
Yearly Trend
Top Affected Vendors
All CWE-23 CVEs (146)
This vulnerability in the file_selector package allows malicious document providers to manipulate file names, potentially overriding internal app cach...
Jan 29, 2025This vulnerability in the image_picker library allows malicious document providers to manipulate file names, potentially overwriting internal app cach...
Jan 29, 2025A relative path traversal vulnerability in FortiSOAR allows authenticated attackers to read arbitrary files by uploading malicious solution packs. Thi...
Aug 12, 2025A relative path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync ...
Feb 11, 2026CVE-2025-13771 is an arbitrary file read vulnerability in WebITR software developed by Uniong. Authenticated remote attackers can exploit relative pat...
Nov 28, 2025This vulnerability allows authenticated users to upload files to restricted directories in IBM Jazz Foundation due to improper path neutralization. It...
Sep 4, 2025CVE-2021-4459 is a path traversal vulnerability in Sunny Boy devices that allows authorized remote attackers to access files and directories outside t...
Aug 27, 2025A path traversal vulnerability in Vedo Suite 2024.17 allows authenticated attackers to read arbitrary files on the filesystem by exploiting an unsanit...
Aug 6, 2025The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability due to missing CSRF protection and a Relative Path Traversal flaw in on...
Dec 16, 2024This vulnerability in Microsoft SharePoint allows an authenticated attacker to access sensitive information they shouldn't have permission to view. It...
Dec 12, 2024This vulnerability in Backstage's TechDocs plugin allows attackers to access the entire AWS S3 or GCS storage bucket contents when using those provide...
Sep 17, 2024This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to read arbitrary files from the server filesystem. The ...
May 29, 2024CVE-2025-60020 is a path traversal vulnerability in nncp (Node to Node Copy) that allows attackers to read or write arbitrary files on the system duri...
Sep 24, 2025CVE-2025-53082 is an arbitrary file deletion vulnerability in Samsung DMS that allows attackers to delete files from unintended filesystem locations. ...
Jul 29, 2025CVE-2026-24909 is a path traversal vulnerability in vlt (vltpkg) that allows attackers to write arbitrary files outside the intended extraction direct...
Jan 27, 2026CVE-2025-64714 is a Local File Inclusion vulnerability in PrivateBin's template-switching feature that allows unauthenticated attackers to read sensit...
Nov 13, 2025This vulnerability allows attackers to perform path traversal attacks during project archive uploads in JetBrains TeamCity, potentially enabling unaut...
Sep 17, 2025A relative path traversal vulnerability in Fortinet FortiManager allows privileged attackers to delete files from the underlying filesystem via crafte...
Jan 14, 2025This vulnerability allows an authorized attacker to perform local spoofing attacks via relative path traversal in Microsoft Defender for Endpoint. Att...
Oct 8, 2024This vulnerability allows authenticated low-privileged attackers to write arbitrary files to any location on the ctrlX OS filesystem via crafted HTTP ...
Apr 30, 2025This vulnerability in JetBrains Rider allows attackers to overwrite arbitrary files during remote debugging sessions. Attackers could potentially exec...
Apr 25, 2025This CVE describes a relative path traversal vulnerability (zipslip) in Apache Solr's configset upload API on Windows systems. Attackers can upload ma...
Jan 27, 2025A path traversal vulnerability in SonicWall Email Security appliances allows attackers to bypass directory restrictions using sequences like '../' to ...
Nov 20, 2025This CVE describes a path traversal vulnerability in Email Logging Interface 2.0 where manipulation of the Username argument allows attackers to acces...
Nov 15, 2025This vulnerability in Vite allows unauthorized access to HTML files on the server regardless of filesystem restrictions when the dev server is exposed...
Sep 8, 2025This vulnerability in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin allows unauthenticated attackers to perform directory...
Aug 16, 2025This vulnerability allows attackers to delete arbitrary files or directories on systems running aimhubio/aim version 3.19.3 through path traversal in ...
Mar 20, 2025This critical path traversal vulnerability in Jeewms allows attackers to access arbitrary files on the server by manipulating the /wmOmNoticeHControll...
Jan 11, 2025A path traversal vulnerability in Pluck CMS 4.7.18 allows unauthenticated attackers to read sensitive files from the server. The vulnerability is limi...
Oct 1, 2024This vulnerability allows privileged attackers to delete arbitrary files from the underlying filesystem via crafted CLI requests in affected Fortinet ...
Nov 12, 2024A relative path traversal vulnerability in FortiWeb web application firewalls allows authenticated attackers to read arbitrary files on the underlying...
Sep 9, 2025This vulnerability in JetBrains TeamCity allows attackers to bypass path validation in the loggingPreset parameter, potentially enabling unauthorized ...
Apr 25, 2025This CVE describes a relative path traversal vulnerability in the s2Member WordPress plugin that allows attackers to access files outside the intended...
Apr 4, 2025This vulnerability in Team+ software allows administrators to move arbitrary system files to the web root directory, potentially exposing sensitive da...
Oct 14, 2024This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to write backup files to arbitrary locations on the serv...
Oct 8, 2024Yealink T21P_E2 phones running firmware 52.84.0.15 have a directory traversal vulnerability in the diagnostic component. Remote attackers with normal ...
Dec 26, 2025Dell Secure Connect Gateway (SCG) versions 5.26.00.00 through 5.30.00.00 contain a relative path traversal vulnerability in a REST API endpoint used f...
Oct 30, 2025A path traversal vulnerability in stangirard/quivr allows attackers to upload files to arbitrary S3 bucket paths by manipulating file paths in upload ...
Mar 20, 2025This path traversal vulnerability in Tsinghua Unigroup Electronic Archives System allows attackers to read arbitrary files by manipulating the 'name' ...
Jan 5, 2025This vulnerability allows attackers to perform path traversal attacks via the backup function's name parameter in cjbi wetech-cms. Remote attackers ca...
Dec 12, 2024This vulnerability allows a malicious or compromised Assemblyline 4 server (or any MITM attacker) to write arbitrary files to any location on the clie...
Aug 9, 2025This CVE describes a path traversal vulnerability in MISP's EventReport.php that allows site-admin users to access files outside the intended director...
Nov 28, 2025Dell PowerProtect DD management console contains a relative path traversal vulnerability that allows authenticated high-privilege attackers to send un...
Jun 26, 2024A relative path traversal vulnerability in Productivity Suite software version 4.4.1.19 allows unauthenticated remote attackers to delete arbitrary di...
Oct 23, 2025This vulnerability in Go's os.Root implementation allows directory traversal to access the parent directory when opening files ending with '../'. It a...
Feb 4, 2026This CVE describes a relative path traversal vulnerability in Erlang/OTP's TFTP file modules (tftp_file.erl). It allows attackers to access files outs...
Feb 20, 2026About CWE-23 (CWE-23)
Our database tracks 146 CVEs classified as CWE-23, with 26 rated critical and 76 rated high severity. The average CVSS score for CWE-23 vulnerabilities is 7.4.
External reference: View CWE-23 on MITRE CWE →
Monitor CWE-23 Vulnerabilities
Get alerted when new CWE-23 CVEs affect your infrastructure.
Start Monitoring Free