In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using t
Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTP
Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.
Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploit
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Parse Server cra
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4
A path traversal vulnerability has been detected in Repox, which allows an attacker to read arbitrary files on the runni
Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execu
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware versions prior to 5.26.119
The High Availability functionality of Yugabyte Anywhere can be abused to write arbitrary
Visual Studio Code Spoofing Vulnerability
A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions
Users authorized to list or watch one type of namespaced custom resource cluster-wide can read custom resources of a dif
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform a direct
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remot
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball s
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is
A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to d
A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, Forti
A vulnerability in the NETCONF service of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote
Office for Android Spoofing Vulnerability
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 8
A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versio
A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classif
A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterio
A vulnerability was found in MuYuCMS 2.2. It has been classified as problematic. Affected is an unknown function of the
A vulnerability was found in MuYuCMS 2.2. It has been declared as problematic. Affected by this vulnerability is an unkn
A vulnerability was found in MuYuCMS 2.2. It has been rated as problematic. Affected by this issue is some unknown funct
Relative path traversal in the Zoom Client SDK before version 5.15.0 may allow an unauthorized user to enable informatio
Sudo-rs, a memory safe implementation of sudo and su, allows users to not have to enter authentication at every sudo att
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc
Multiple vulnerabilities in the API and web-based management interfaces of Cisco Expressway Series and Cisco TelePresenc
Path traversal vulnerability exists in CAMS for HIS Server contained in the following Yokogawa Electric products: CENTUM
A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of
In some non-default installations of Esri Portal for ArcGIS versions 10.9.1 and below, a directory traversal issue may a
There is a path traversal vulnerability in CAMS for HIS Log Server contained in the following Yokogawa Electric products
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module
An attacker could utilize a function in MDT AutoSave versions prior to v6.02.06 that permits changing a designated path
The affected products are vulnerable to directory traversal, which may allow an attacker to obtain arbitrary operating s
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing
TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules.
An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWin
Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when access
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started