The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat
Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able
Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a u
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst
A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.
IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to
An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln
The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to in
Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signe
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar
Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
Relative Path Traversal vulnerability in Shah Alom Delete Comments By Status delete-comments-by-status allows Path Trave
Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack:
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versio
An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den
Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'res
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior
Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff
Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Ev
AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions
The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a
The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attacker
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2
Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r
A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit
IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo
There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure.
Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote at
Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application
WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit
Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access t
A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 a
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting
Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc
The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu
NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary fil
A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenti
A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers
A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab
Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the file
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerabili
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started