The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize 'dir\..\..\filename' (multiple internal backslash dot dot) sequences that can resolve to a location that is outside of that directory.
Volume of CVEs assigned to CWE-31 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-2044CRITICAL pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticat | Mar 7, 2024 | 9.9 | 82 | NO | YES |
CVE-2024-36857HIGH Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface. | Jun 4, 2024 | 7.5 | 32 | NO | YES |
CVE-2024-24998HIGH A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | Apr 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-41376HIGH dzzoffice 2.02.1 is vulnerable to Directory Traversal via user/space/about.php. | Aug 5, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-28088HIGH LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call. This bypasses the intended beh | Mar 4, 2024 | 8.1 | 23 | NO | NO |
CVE-2019-6268HIGH RAD SecFlow-2 devices with Hardware 0202, Firmware 4.1.01.63, and U-Boot 2010.12 allow URIs beginning with /.. for Directory Traversal, as demonstrated by reading /etc/shadow. | Mar 8, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-35431HIGH ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via photoBase64. An unauthenticated user can download local files from the server. NOTE: Third parties have indic | May 30, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-35429MEDIUM ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via eventRecord. | May 30, 2024 | 6.5 | 20 | NO | NO |
CVE-2024-25840HIGH In the module "Account Manager | Sales Representative & Dealers | CRM" (prestasalesmanager) up to 9.0 from Presta World for PrestaShop, a guest can download personal information wi | Feb 27, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-35860MEDIUM A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information via the dir parameter to listi | Jun 13, 2024 | 5.3 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.