The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.
Volume of CVEs assigned to CWE-36 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
131 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20250HIGH In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field i | Feb 5, 2019 | 7.8 | 98 | YES | YES |
CVE-2024-48248HIGH NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the | Mar 4, 2025 | 8.6 | 97 | YES | YES |
CVE-2024-13159HIGH Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit | Jan 14, 2025 | 7.5 | 97 | YES | YES |
CVE-2024-13161HIGH Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit | Jan 14, 2025 | 7.5 | 96 | YES | YES |
CVE-2024-13160HIGH Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit | Jan 14, 2025 | 7.5 | 96 | YES | YES |
CVE-2023-3765CRITICAL Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0. | Jul 19, 2023 | 10.0 | 77 | NO | YES |
CVE-2025-57790HIGH A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to r | Aug 20, 2025 | 8.8 | 55 | NO | YES |
CVE-2025-46822HIGH OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, ins | May 21, 2025 | 7.7 | 47 | NO | YES |
CVE-2025-34392CRITICAL Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by | Dec 10, 2025 | 9.8 | 45 | NO | NO |
CVE-2026-57211CRITICAL RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded ba | Jul 10, 2026 | 10.0 | 43 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.