DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm
An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.e
In Ankitects Anki before 25.02.6, crafted sound file references could cause files to be written to arbitrary locations o
The API used to interact with documents in the application contains a flaw that allows an authenticated attacker to read
Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$tar
Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of s
esm.sh is a nobuild content delivery network(CDN) for modern web development. In 136 and earlier, a Local File Inclusion
LangBot is a global IM bot platform designed for LLMs. In versions 4.1.0 up to but not including 4.3.5, authorized attac
RaspberryMatic is an open-source operating system for HomeMatic internet-of-things devices. RaspberryMatic / OCCU prior
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to write any file on the system w
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and
mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un
The DVC from TRCore has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows un
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to ex
A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal
Windows Hyper-V Remote Code Execution Vulnerability
A specially crafted Zip file containing path traversal characters can be imported to the CyberPower PowerPanel serve
gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to
Path traversal vulnerability in the web server of the Toshiba printer enables attacker to overwrite orginal files or add
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.Th
Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.
NiceGUI is an easy-to-use, Python-based UI framework. A local file inclusion is present in the NiceUI leaflet component
mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a def
TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple loca
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "a
In JetBrains YouTrack before 2024.3.51866 system takeover was possible through path traversal in plugin sandbox
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Ar
NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-de
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used
Relative Path Traversal vulnerability in ZkTeco-based OEM devices allows an attacker to access any file on the system.
A directory traversal vulnerability exists in the /api/download-project-pdf endpoint of the stitionai/devika repository,
The application zips all the files in the folder specified by the user, which allows an attacker to read arbitrary files
Raiden MAILD Remote Management System from Team Johnlong Software has a Relative Path Traversal vulnerability, allowing
IDURAR is open source ERP CRM accounting invoicing software. The vulnerability exists in the corePublicRouter.js file. U
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing unauthenticated remote
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remo
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote att
Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusi
The D-Link DSL6740C modem has a Path Traversal Vulnerability, allowing unauthenticated remote attackers to exploit this
The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started