Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-23

57
CRITICAL
214
HIGH
173
MEDIUM
18
LOW
484 CVEs · Page 4/10
8.8
CVE-2024-54449

The API used to interact with documents in the application contains two endpoints with a flaw that allows an authenticat

8.8
CVE-2025-32017

Umbraco is a free and open source .NET content management system. Authenticated users to the Umbraco backoffice are able

8.8
CVE-2025-34510

Sitecore Experience Manager (XM), Experience Platform (XP), and Experience Commerce (XC) versions 9.0 through 9.3 and 10

8.8
CVE-2025-48817

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

8.8
CVE-2025-7619

BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a u

8.8
CVE-2025-55115

A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the syst

8.8
CVE-2025-62498

A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The

8.6
CVE-2025-58760

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.

8.4
CVE-2025-33112

IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to

8.4
CVE-2025-54317

An issue was discovered in Logpoint before 7.6.0. An attacker with operator privileges can exploit a path traversal vuln

8.1
CVE-2025-2007

The Import Export Suite for CSV and XML Datafeed plugin for WordPress is vulnerable to arbitrary file deletion due to in

8.1
CVE-2025-32409

Ratta SuperNote A6 X2 Nomad before December 2024 allows remote code execution because an arbitrary firmware image (signe

8.1
CVE-2025-66626

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Version

7.8
CVE-2025-10203

Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrar

7.8
CVE-2025-62552

Relative path traversal in Microsoft Office Access allows an unauthorized attacker to execute code locally.

7.7
CVE-2025-54531

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

7.5
CVE-2025-25130

Relative Path Traversal vulnerability in Shah Alom Delete Comments By Status delete-comments-by-status allows Path Trave

7.5
CVE-2025-27610

Rack provides an interface for developing web applications in Ruby. Prior to versions 2.2.13, 3.0.14, and 3.1.12, `Rack:

7.5
CVE-2025-2056

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versio

7.5
CVE-2024-9363

An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to den

7.5
CVE-2025-27553

Relative Path Traversal vulnerability in Apache Commons VFS before 2.10.0. The FileObject API in Commons VFS has a 'res

7.5
CVE-2025-29789

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior

7.5
CVE-2025-30207

Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff

7.5
CVE-2025-47445

Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Ev

7.5
CVE-2025-48957

AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions

7.5
CVE-2025-7146

The iPublish System developed by Jhenggao has an Arbitrary File Reading vulnerability, allowing unauthenticated remote a

7.5
CVE-2025-9639

The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attacker

7.5
CVE-2025-55748

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2

7.5
CVE-2025-11898

Agentflow developed by Flowring has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers t

7.5
CVE-2025-58078

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnera

7.5
CVE-2025-58429

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit

7.5
CVE-2025-55752

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r

7.5
CVE-2025-58464

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit

7.5
CVE-2025-13161

IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo

7.5
CVE-2025-12097

There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure.

7.5
CVE-2025-15015

Enterprise Cloud Database developed by Ragic has a Arbitrary File Read vulnerability, allowing unauthenticated remote at

7.5
CVE-2025-57403

Cola Dnslog v1.3.2 is vulnerable to Directory Traversal. When a DNS query for a TXT record is processed, the application

7.5
CVE-2025-15225

WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit

7.4
CVE-2025-52922

Innoshop through 0.4.1 allows directory traversal via FileManager API endpoints. An authenticated attacker with access t

7.2
CVE-2025-26349

A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 a

7.2
CVE-2024-10513

A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting

7.2
CVE-2025-53779

Relative path traversal in Windows Kerberos allows an authorized attacker to elevate privileges over a network.

7.1
CVE-2024-54461

The file names constructed within file_selector are missing sanitization checks leaving them vulnerable to malicious doc

7.1
CVE-2024-54462

The file names constructed within image_picker are missing sanitization checks leaving them vulnerable to malicious docu

7.1
CVE-2025-23360

NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary fil

7.1
CVE-2025-24350

A vulnerability in the “Certificates and Keys” functionality of the web application of ctrlX OS allows a remote authenti

6.8
CVE-2024-48892

A relative path traversal vulnerability [CWE-23] in FortiSOAR 7.6.0, 7.5.0 through 7.5.1, 7.4 all versions, 7.3 all vers

6.8
CVE-2025-58456

A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerab

6.5
CVE-2025-0822

Bit Assist plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.5.2 via the file

6.5
CVE-2025-1588

A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerabili

Frequently Asked Questions

What is CWE-23?

CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-23?

There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.

How can I protect against CWE-23 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.

Detect CWE-23 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.

Get Started