CWE-23: CWE-23

146
Total CVEs
26
Critical
76
High
7.4
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
12
2025
69
2024
34
2023
11
2022
6

Top Affected Vendors

1 Fortinet 9
2 Microsoft 5
3 Jetbrains 5
4 Trcore 4
5 Dell 3
6 Qnap 3
7 Apache 3
8 Rockwellautomation 2
9 Flutter 2
10 Ibm 2

All CWE-23 CVEs (146)

CVE-2024-54461
7.1

This vulnerability in the file_selector package allows malicious document providers to manipulate file names, potentially overriding internal app cach...

Jan 29, 2025
CVE-2024-54462
7.1

This vulnerability in the image_picker library allows malicious document providers to manipulate file names, potentially overwriting internal app cach...

Jan 29, 2025
CVE-2024-48892
6.8

A relative path traversal vulnerability in FortiSOAR allows authenticated attackers to read arbitrary files by uploading malicious solution packs. Thi...

Aug 12, 2025
CVE-2025-58467
6.5

A relative path traversal vulnerability in Qsync Central allows authenticated attackers to read arbitrary files on the system. This affects all Qsync ...

Feb 11, 2026
CVE-2025-13771
6.5

CVE-2025-13771 is an arbitrary file read vulnerability in WebITR software developed by Uniong. Authenticated remote attackers can exploit relative pat...

Nov 28, 2025
CVE-2025-25048
6.5

This vulnerability allows authenticated users to upload files to restricted directories in IBM Jazz Foundation due to improper path neutralization. It...

Sep 4, 2025
CVE-2021-4459
6.5

CVE-2021-4459 is a path traversal vulnerability in Sunny Boy devices that allows authorized remote attackers to access files and directories outside t...

Aug 27, 2025
CVE-2025-51052
6.5

A path traversal vulnerability in Vedo Suite 2024.17 allows authenticated attackers to read arbitrary files on the filesystem by exploiting an unsanit...

Aug 6, 2025
CVE-2024-12645
6.5

The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability due to missing CSRF protection and a Relative Path Traversal flaw in on...

Dec 16, 2024
CVE-2024-49062
6.5

This vulnerability in Microsoft SharePoint allows an authenticated attacker to access sensitive information they shouldn't have permission to view. It...

Dec 12, 2024
CVE-2024-45816
6.5

This vulnerability in Backstage's TechDocs plugin allows attackers to access the entire AWS S3 or GCS storage bucket contents when using those provide...

Sep 17, 2024
CVE-2024-36362
6.5

This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to read arbitrary files from the server filesystem. The ...

May 29, 2024
CVE-2025-60020
6.4

CVE-2025-60020 is a path traversal vulnerability in nncp (Node to Node Copy) that allows attackers to read or write arbitrary files on the system duri...

Sep 24, 2025
CVE-2025-53082
6.1

CVE-2025-53082 is an arbitrary file deletion vulnerability in Samsung DMS that allows attackers to delete files from unintended filesystem locations. ...

Jul 29, 2025
CVE-2026-24909
5.9

CVE-2026-24909 is a path traversal vulnerability in vlt (vltpkg) that allows attackers to write arbitrary files outside the intended extraction direct...

Jan 27, 2026
CVE-2025-64714
5.8

CVE-2025-64714 is a Local File Inclusion vulnerability in PrivateBin's template-switching feature that allows unauthenticated attackers to read sensit...

Nov 13, 2025
CVE-2025-59456
5.5

This vulnerability allows attackers to perform path traversal attacks during project archive uploads in JetBrains TeamCity, potentially enabling unaut...

Sep 17, 2025
CVE-2024-32115
5.5

A relative path traversal vulnerability in Fortinet FortiManager allows privileged attackers to delete files from the underlying filesystem via crafte...

Jan 14, 2025
CVE-2024-43614
5.5

This vulnerability allows an authorized attacker to perform local spoofing attacks via relative path traversal in Microsoft Defender for Endpoint. Att...

Oct 8, 2024
CVE-2025-24343
5.4

This vulnerability allows authenticated low-privileged attackers to write arbitrary files to any location on the ctrlX OS filesystem via crafted HTTP ...

Apr 30, 2025
CVE-2025-43016
5.4

This vulnerability in JetBrains Rider allows attackers to overwrite arbitrary files during remote debugging sessions. Attackers could potentially exec...

Apr 25, 2025
CVE-2024-52012
5.4

This CVE describes a relative path traversal vulnerability (zipslip) in Apache Solr's configset upload API on Windows systems. Attackers can upload ma...

Jan 27, 2025
CVE-2025-40605
5.3

A path traversal vulnerability in SonicWall Email Security appliances allows attackers to bypass directory restrictions using sequences like '../' to ...

Nov 20, 2025
CVE-2025-13199
5.3

This CVE describes a path traversal vulnerability in Email Logging Interface 2.0 where manipulation of the Username argument allows attackers to acces...

Nov 15, 2025
CVE-2025-58752
5.3

This vulnerability in Vite allows unauthorized access to HTML files on the server regardless of filesystem restrictions when the dev server is exposed...

Sep 8, 2025
CVE-2025-8464
5.3

This vulnerability in the Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin allows unauthenticated attackers to perform directory...

Aug 16, 2025
CVE-2024-6483
5.3

This vulnerability allows attackers to delete arbitrary files or directories on systems running aimhubio/aim version 3.19.3 through path traversal in ...

Mar 20, 2025
CVE-2025-0390
5.3

This critical path traversal vulnerability in Jeewms allows attackers to access arbitrary files on the server by manipulating the /wmOmNoticeHControll...

Jan 11, 2025
CVE-2024-9405
5.3

A path traversal vulnerability in Pluck CMS 4.7.18 allows unauthenticated attackers to read sensitive files from the server. The vulnerability is limi...

Oct 1, 2024
CVE-2024-32116
5.1

This vulnerability allows privileged attackers to delete arbitrary files from the underlying filesystem via crafted CLI requests in affected Fortinet ...

Nov 12, 2024
CVE-2025-53609
4.9

A relative path traversal vulnerability in FortiWeb web application firewalls allows authenticated attackers to read arbitrary files on the underlying...

Sep 9, 2025
CVE-2025-46433
4.9

This vulnerability in JetBrains TeamCity allows attackers to bypass path validation in the loggingPreset parameter, potentially enabling unauthorized ...

Apr 25, 2025
CVE-2025-32137
4.9

This CVE describes a relative path traversal vulnerability in the s2Member WordPress plugin that allows attackers to access files outside the intended...

Apr 4, 2025
CVE-2024-9923
4.9

This vulnerability in Team+ software allows administrators to move arbitrary system files to the web root directory, potentially exposing sensitive da...

Oct 14, 2024
CVE-2024-47949
4.9

This CVE describes a path traversal vulnerability in JetBrains TeamCity that allows attackers to write backup files to arbitrary locations on the serv...

Oct 8, 2024
CVE-2025-66737
4.3

Yealink T21P_E2 phones running firmware 52.84.0.15 have a directory traversal vulnerability in the diagnostic component. Remote attackers with normal ...

Dec 26, 2025
CVE-2025-46363
4.3

Dell Secure Connect Gateway (SCG) versions 5.26.00.00 through 5.30.00.00 contain a relative path traversal vulnerability in a REST API endpoint used f...

Oct 30, 2025
CVE-2024-6583
4.3

A path traversal vulnerability in stangirard/quivr allows attackers to upload files to arbitrary S3 bucket paths by manipulating file paths in upload ...

Mar 20, 2025
CVE-2025-0225
4.3

This path traversal vulnerability in Tsinghua Unigroup Electronic Archives System allows attackers to read arbitrary files by manipulating the 'name' ...

Jan 5, 2025
CVE-2024-12482
4.3

This vulnerability allows attackers to perform path traversal attacks via the backup function's name parameter in cjbi wetech-cms. Remote attackers ca...

Dec 12, 2024
CVE-2025-55013
4.2

This vulnerability allows a malicious or compromised Assemblyline 4 server (or any MITM attacker) to write arbitrary files to any location on the clie...

Aug 9, 2025
CVE-2025-66386
4.1

This CVE describes a path traversal vulnerability in MISP's EventReport.php that allows site-admin users to access files outside the intended director...

Nov 28, 2025
CVE-2024-37138
4.1

Dell PowerProtect DD management console contains a relative path traversal vulnerability that allows authenticated high-privilege attackers to send un...

Jun 26, 2024
CVE-2025-60023
4.0

A relative path traversal vulnerability in Productivity Suite software version 4.4.1.19 allows unauthenticated remote attackers to delete arbitrary di...

Oct 23, 2025
CVE-2025-22873
3.8

This vulnerability in Go's os.Root implementation allows directory traversal to access the parent directory when opening files ending with '../'. It a...

Feb 4, 2026
CVE-2026-21620
N/A

This CVE describes a relative path traversal vulnerability in Erlang/OTP's TFTP file modules (tftp_file.erl). It allows attackers to access files outs...

Feb 20, 2026

About CWE-23 (CWE-23)

Our database tracks 146 CVEs classified as CWE-23, with 26 rated critical and 76 rated high severity. The average CVSS score for CWE-23 vulnerabilities is 7.4.

External reference: View CWE-23 on MITRE CWE →

Monitor CWE-23 Vulnerabilities

Get alerted when new CWE-23 CVEs affect your infrastructure.

Start Monitoring Free