The DVC from TRCore has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion +
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to
A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relativ
Oceanic is a NodeJS library for interfacing with Discord. Prior to version 1.10.4, input to functions such as `Client.re
In JetBrains TeamCity before 2022.04.7, 2022.10.6, 2023.05.6, 2023.11.5, 2024.03.2 path traversal allowing to read files
Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDoc
Microsoft SharePoint Information Disclosure Vulnerability
The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local w
: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.Th
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacke
Relative path traversal in Microsoft Defender for Endpoint allows an authorized attacker to perform spoofing locally.
In JetBrains TeamCity before 2023.11.2 limited directory traversal was possible in the Kotlin DSL documentation
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
An incorrect limitation of a path to a restricted directory (path traversal) has been detected in Pluck CMS, affecting v
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and befor
An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Securit
A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traver
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remo
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
The Team+ from TEAMPLUS TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnera
A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affect
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is th
A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has
Lif Auth Server is a server for validating logins, managing information, and account recovery for Lif Accounts. The issu
Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 on DDMC contain a relative path t
Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6.
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For
If exploited an attacker could traverse the file system to access files or directories that would otherwise be inaccess
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
Relative Path Traversal in GitHub repository mintplex-labs/anything-llm prior to 0.0.1.
Deepin-Compressor is the default archive manager of Deepin Linux OS. Prior to 5.12.21, there's a path traversal vulnerab
Relative Path Traversal vulnerability in ForgeRock Access Management Web Policy Agent allows Authentication Bypass. This
Relative Path Traversal vulnerability in ForgeRock Access Management Java Policy Agent allows Authentication Bypass. Thi
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 an
Microsoft Exchange Server Remote Code Execution Vulnerability
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 an
Microsoft Defender for IoT Elevation of Privilege Vulnerability
A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 an
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or d
Windows Kernel Elevation of Privilege Vulnerability
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started