ORY Oathkeeper is an Identity & Access Proxy (IAP) and Access Control Decision API that authorizes HTTP requests based o
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences
A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the hos
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
A path traversal vulnerability in LXD's instance template processing allows an attacker with container edit permissions,
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in John
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path vali
In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling w
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate reque
MarkUs is a web application for the submission and grading of student assignments. Prior to 2.9.1, instructors are able
A vulnerability has been identified in ROS# (All versions < V2.2.2). Affected versions contain a path traversal vulnerab
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel:
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by re
Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code ov
Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network.
Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.
LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset re
Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before
OpenClaw before 2026.4.10 contains an arbitrary file read vulnerability in QQBot media tags that allows attackers to ref
Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f
Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Tr
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attack
SciTokens C++ is a minimal library for creating and using SciTokens from C or C++. Prior to version 1.4.1, scitokens-cpp
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write f
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti
Dell Unisphere for PowerMax, version(s) 10.2, contain(s) a Relative Path Traversal vulnerability. A low privileged attac
Stirling-PDF is a locally hosted web application that performs various operations on PDF files. In versions prior to 2.5
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is ena
ThreatSonar Anti-Ransomware developed by TeamT5 has an Arbitrary File Deletion vulnerability. Authenticated remote attac
A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation
Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial
ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack
A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitiz
Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network.
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal (Zip Slip) in Waterfall WF-500 RX Host in version 7.9.
Relative path traversal in Windows User Interface Core allows an authorized attacker to elevate privileges locally.
Relative path traversal in .NET Framework allows an unauthorized attacker to elevate privileges locally.
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, the /snippets/*filepath route handler ser
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler`
@sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of fil
Statistics Database System developed by Gotac has an Arbitrary File Read vulnerability, allowing unauthenticated remote
apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before 1.1.1
NavigaTUM is a website and API to search for rooms, buildings and other places. Prior to commit 86f34c7, there is a path
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature th
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 136 CVE records associated with CWE-23 in our database. Of these, 13 are critical severity, 68 are high severity, and 37 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started