calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to version 9.
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.restore(env, b
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
Relative path traversal in Visual Studio Code allows an unauthorized attacker to disclose information locally.
AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Came
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versi
Anviz CX7 Firmware is vulnerable to an authenticated CSV upload which allows path traversal to overwrite arbitrary files
DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to explo
Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Tr
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is u
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs betwee
It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For examp
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 a
A vulnerability in allegroai/clearml versions up to and including 1.16.5 allows for relative path traversal when extract
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file mo
Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction
XWiki Platform is a generic wiki platform. Versions prior to 18.1.0-rc-1, 17.10.3, 17.4.9, and 16.10.17 allow access to
Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitra
Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the docume
Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints
Canonical MicroCeph versions from the squid and tentacle track are vulnerable to a path traversal issue in the remote-im
Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr
Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0.
A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overw
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extrac
A Path Traversal vulnerability exists in Quick.CMS through the URI path component of HTTP requests, where the server fai
hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenat
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to cre
A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 a
PBXCoreREST/Controllers/Files/PostController.php in MikoPBX through 2024.1.114 allows uploading a PHP script to an arbit
When uploading organism or sequence data via the web interface, GMOD Apollo will unzip and inspect the files and wil
A missing protection against path traversal allows to access any file on the server.
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the
Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue af
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabili
A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope vers
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.
Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives ("Zip Slip"). A remote, authenticated at
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started