Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-23

13
CRITICAL
68
HIGH
37
MEDIUM
3
LOW
136 CVEs · Page 2/3
7.5
CVE-2026-30345

A zip slip vulnerability in the Admin import functionality of CTFd v3.8.1-18-gdb5a18c4 allows attackers to write arbitra

7.5
CVE-2026-31831

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/

7.5
CVE-2026-27489

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0,

7.5
CVE-2026-8073

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del

7.5
CVE-2026-8361

A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome

7.5
CVE-2025-41271

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Console WebUI in Waterfall WF-500 TX and RX Hos

7.5
CVE-2026-10073

DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to

7.5
CVE-2026-54066

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Trave

7.5
CVE-2026-8023

Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, ava

7.5
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform UR

7.5
CVE-2026-18907

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via direc

7.5
CVE-2026-10595

A path traversal vulnerability exists in parisneo/lollms version 2.1.0, specifically in the SPA catch-all route implemen

7.5
CVE-2026-63490

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handleb

7.5
CVE-2026-63043

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue

7.5
CVE-2026-78212

4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remot

7.5
CVE-2026-66907

Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from

7.3
CVE-2026-7404

A weakness has been identified in getsimpletool mcpo-simple-server up to 0.2.0. Affected is the function delete_shared_p

7.3
CVE-2026-41046

A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to

7.3
CVE-2026-72677

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path T

7.2
CVE-2026-25951

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.2.11, there is a flaw in the path s

7.2
CVE-2026-33733

EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, the admin template manag

7.2
CVE-2026-8134

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTempl

7.2
CVE-2026-61343

LibreBooking's email template editor save action passes the submitted template name directly into the destination file p

7.1
CVE-2026-29778

pyLoad is a free and open-source download manager written in Python. From version 0.5.0b3.dev13 to 0.5.0b3.dev96, the ed

7.1
CVE-2026-22070

ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.

7.1
CVE-2026-43616

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t

7.1
CVE-2026-48569

Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

7.1
CVE-2026-57988

Relative path traversal in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a networ

7.1
CVE-2026-50181

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.64.0, Langroid's `Rea

7.1
CVE-2026-53416

Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via loca

7.1
CVE-2026-81838

A relative path traversal issue in the zip extraction functionality in AWS diagram-as-code (awsdac) in versions 0.10 thr

6.8
CVE-2026-58522

Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

6.8
CVE-2026-50426

Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network.

6.8
CVE-2026-62843

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec

6.7
CVE-2026-39814

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb

6.7
CVE-2026-34926 KEV

A directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker t

6.5
CVE-2026-23888

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows mali

6.5
CVE-2026-23890

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicio

6.5
CVE-2025-58467

A relative path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user acc

6.5
CVE-2026-20078

Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr

6.5
CVE-2026-20081

Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitr

6.5
CVE-2025-48977

Relative Path Traversal vulnerability in Apache Ignite REST API. Authenticated REST API users can read any file on the

6.5
CVE-2026-47287

Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.

6.5
CVE-2026-59149

Mockoon provides way to design and run mock APIs. Prior to 9.7.0, a FILE response whose filePath embeds request data is

6.5
CVE-2026-55474

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the rout

6.5
CVE-2026-51026

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a

6.5
CVE-2026-58481

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `AgentRuntime` promises scoped fil

6.5
CVE-2026-18192

VIN-DS783E-E6 developed by Vacron has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to e

6.5
CVE-2026-56794

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains a Relative Path Traversal vulnerability. A lo

6.5
CVE-2026-62837

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw

Frequently Asked Questions

What is CWE-23?

CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-23?

There are 136 CVE records associated with CWE-23 in our database. Of these, 13 are critical severity, 68 are high severity, and 37 are medium severity.

How can I protect against CWE-23 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.

Detect CWE-23 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.

Get Started