Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-23

Relative Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.

457
Assigned CVEs
85th
Commonality Rank
7.3
Avg CVSS
1.1%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-23 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2013
13 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

457 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-64446CRITICAL
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWe
Nov 14, 20259.899YESYES
CVE-2024-27199HIGH
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
Mar 4, 20247.397YESYES
CVE-2021-40870CRITICAL
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to ex
Sep 13, 20219.897YESYES
CVE-2020-5410HIGH
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through
Jun 2, 20207.597YESYES
CVE-2026-34926MEDIUM
A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code
May 21, 20266.780YESNO
CVE-2020-5405MEDIUM
Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through
Mar 5, 20206.571NOYES
CVE-2022-23854HIGH
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on th
Dec 23, 20227.569NOYES
CVE-2025-55752HIGH
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This intr
Oct 27, 20257.567NONO
CVE-2020-17518HIGH
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER
Jan 5, 20217.562NOYES
CVE-2023-34990CRITICAL
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted we
Dec 18, 20249.860NOYES
View all 457 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
9%
10%
4.0-4.9
9%
19%
5.0-5.9
15%
16%
6.0-6.9
31%
26%
7.0-7.9
17%
11%
8.0-8.9
16%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
1.1% of CVEs· 91st percentile
Metasploit
5 CVEs
1.1% of CVEs· 88th percentile
Nuclei
18 CVEs
3.9% of CVEs· 94th percentile
ExploitDB
4 CVEs
0.9% of CVEs· 80th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products