CWE-24: CWE-24

26
Total CVEs
1
Critical
12
High
6.6
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
2
2025
20
2024
2
2023
1
2022
1

Top Affected Vendors

1 Esafenet 1
2 Infodraw 1
3 Easyspider 1
4 Google 1
5 Go Fastdfs Project 1
6 Gnu 1
7 Getsol 1
8 Emlog 1
9 Apache 1
10 Efforthye 1

All CWE-24 CVEs (26)

CVE-2025-61318
9.1

Emlog Pro 2.5.20 contains an arbitrary file deletion vulnerability in admin/template.php and admin/plugin.php components. Attackers can exploit direct...

Dec 8, 2025
CVE-2025-54769
8.8

This vulnerability allows authenticated read-only users to upload files and perform directory traversal attacks, enabling them to overwrite existing P...

Jul 29, 2025
CVE-2025-53513
8.8

This vulnerability allows any authenticated user on a Juju controller to upload malicious charms via the /charms endpoint due to insufficient authoriz...

Jul 8, 2025
CVE-2021-33036
8.8

This CVE allows a user who can escalate to the yarn user account in Apache Hadoop to execute arbitrary commands as the root user, leading to complete ...

Jun 15, 2022
CVE-2025-60344
8.6

An unauthenticated Local File Inclusion vulnerability in D-Link DSR series routers allows remote attackers to read sensitive configuration files conta...

Oct 21, 2025
CVE-2023-53691
8.3

This vulnerability allows attackers to upload arbitrary files via directory traversal in Hikvision's iSecure Center platform. It affects Hikvision CSM...

Oct 22, 2025
CVE-2025-63298
8.2

An authenticated admin user in SourceCodester Pet Grooming Management System 1.0 can exploit a path traversal vulnerability in admin/manage_website.ph...

Oct 30, 2025
CVE-2025-67364
7.5

CVE-2025-67364 is a critical path traversal vulnerability in fast-filesystem-mcp version 3.4.0 that allows attackers to bypass directory access restri...

Jan 7, 2026
CVE-2025-51661
7.5

A path traversal vulnerability in FileCodeBox v2.2 and earlier allows unauthenticated remote attackers to write arbitrary files anywhere on the server...

Nov 19, 2025
CVE-2025-48050
7.5

This vulnerability in DOMPurify's development helper script allows path traversal attacks when the server.js script is manually started. It affects de...

May 15, 2025
CVE-2025-57618
7.3

A path traversal vulnerability in FastX3 allows unauthenticated attackers to read arbitrary server files, including configuration files containing JWT...

Oct 14, 2025
CVE-2023-1800
7.3

This critical vulnerability in go-fastdfs allows attackers to perform path traversal attacks via the file upload handler. By manipulating upload reque...

Apr 2, 2023
CVE-2025-27920
KEV EPSS 46.1% 7.2

CVE-2025-27920 is a directory traversal vulnerability in Output Messenger that allows attackers to access sensitive files outside intended directories...

May 5, 2025
CVE-2025-57563
6.5

This vulnerability allows unauthenticated attackers to read arbitrary files on systems running vulnerable versions of StarNet FastX. Attackers can exp...

Oct 14, 2025
CVE-2025-67845
6.4

A directory traversal vulnerability in Mintlify Platform's static asset proxy endpoint allows attackers to inject malicious web scripts or HTML via cr...

Dec 19, 2025
CVE-2025-61189
6.3

Jeecgboot versions 3.8.2 and earlier contain a path traversal vulnerability in the /sys/comment/addFile endpoint that allows attackers to upload files...

Oct 1, 2025
CVE-2025-47423
5.8

This vulnerability allows unauthenticated remote attackers to read arbitrary files on servers running Personal Weather Station Dashboard 12_lts via di...

May 7, 2025
CVE-2025-43928
5.8

Infodraw Media Relay Service 7.1.0.0 contains a path traversal vulnerability in its web server on port 12654. Attackers can read arbitrary files, incl...

Apr 20, 2025
CVE-2026-21436
5.5

This vulnerability in eopkg allows malicious packages to bypass the --destdir parameter and install files outside the intended directory. Only users i...

Jan 1, 2026
CVE-2025-32807
5.3

A path traversal vulnerability in FusionDirectory allows remote attackers to read arbitrary files ending with .png, .svg, or .xpm extensions via the i...

Apr 11, 2025
CVE-2025-46646
4.5

This vulnerability in Artifex Ghostscript involves improper handling of overlong UTF-8 encoding in the decode_utf8 function, which could allow attacke...

Apr 26, 2025
CVE-2025-26427
4.4

This CVE describes a path traversal vulnerability in Android that allows unauthorized access to Android/data directories. Attackers could potentially ...

Sep 4, 2025
CVE-2025-56760
4.3

This vulnerability allows attackers to write arbitrary files to the server when Memos 0.22 is configured with local storage. Attackers can exploit the...

Sep 3, 2025
CVE-2024-10379
4.3

This CVE describes a path traversal vulnerability in ESAFENET CDG 5 that allows attackers to read arbitrary files on the server by manipulating the de...

Oct 25, 2024
CVE-2024-6746
4.3

This vulnerability allows local network attackers to perform path traversal attacks in EasySpider 0.6.2 on Windows. By manipulating HTTP GET requests ...

Jul 15, 2024
CVE-2025-45582
4.1

GNU Tar through version 1.35 contains a directory traversal vulnerability that allows file overwrite via a two-step process using crafted TAR archives...

Jul 11, 2025

About CWE-24 (CWE-24)

Our database tracks 26 CVEs classified as CWE-24, with 1 rated critical and 12 rated high severity. The average CVSS score for CWE-24 vulnerabilities is 6.6.

External reference: View CWE-24 on MITRE CWE →

Monitor CWE-24 Vulnerabilities

Get alerted when new CWE-24 CVEs affect your infrastructure.

Start Monitoring Free