Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-36

Absolute Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize absolute path sequences such as "/abs/path" that can resolve to a location that is outside of that directory.

131
Assigned CVEs
154th
Commonality Rank
7.1
Avg CVSS
3.8%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-36 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2017
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

131 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20250HIGH
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field i
Feb 5, 20197.898YESYES
CVE-2024-48248HIGH
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the
Mar 4, 20258.697YESYES
CVE-2024-13159HIGH
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit
Jan 14, 20257.597YESYES
CVE-2024-13161HIGH
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit
Jan 14, 20257.596YESYES
CVE-2024-13160HIGH
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit
Jan 14, 20257.596YESYES
CVE-2023-3765CRITICAL
Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
Jul 19, 202310.077NOYES
CVE-2025-57790HIGH
A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access through a path traversal issue. The vulnerability may lead to r
Aug 20, 20258.855NOYES
CVE-2025-46822HIGH
OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, ins
May 21, 20257.747NOYES
CVE-2025-34392CRITICAL
Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL defined in an attacker-controlled WSDL that is later loaded by
Dec 10, 20259.845NONO
CVE-2026-57211CRITICAL
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded ba
Jul 10, 202610.043NONO
View all 131 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
8%
10%
4.0-4.9
9%
19%
5.0-5.9
21%
16%
6.0-6.9
34%
26%
7.0-7.9
15%
11%
8.0-8.9
9%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
5 CVEs
3.8% of CVEs· 98th percentile
Metasploit
2 CVEs
1.5% of CVEs· 91st percentile
Nuclei
8 CVEs
6.1% of CVEs· 97th percentile
ExploitDB
2 CVEs
1.5% of CVEs· 86th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products