AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may all
A zip slip vulnerability in XINJE XD/E Series PLC Program Tool up to version v3.5.1 can provide an attacker with arbitra
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vu
Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privil
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni
The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an a
The affected product is vulnerable to directory traversal, which may allow an attacker to access unauthorized files and
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user als
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to 0.1.5 are vulnerable to Relative Path Trav
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative p
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and ol
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially expl
A vulnerability in Cisco Nexus Dashboard could allow an authenticated, remote attacker to write arbitrary files on an af
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to u
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-leve
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path
An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the b
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the curr
A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for
A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, th
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file tr
The GOautodial API prior to commit 3c3a979 made on October 13th, 2021 takes a user-supplied “action” parameter and appen
SUSI.AI is an intelligent Open Source personal assistant. SUSI.AI Server before version d27ed0f has a directory traversa
AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy
OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 1
A path traversal vulnerability exists in Esri ArcGIS Earth versions 1.11.0 and below which allows arbitrary file creatio
OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning man
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the l
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload
Rasa is an open source machine learning framework to automate text-and voice-based conversations. In affected versions a
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker t
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unautho
TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an att
SABnzbd is an open source binary newsreader. A vulnerability was discovered in SABnzbd that could trick the `filesystem.
bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee438
An attacker could use a specially crafted URL to delete or read files outside the WebAccess/NMS's (versions prior to 3.0
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.miles
A relative path traversal attack in the B. Braun OnlineSuite Version AP 3.0 and earlier allows unauthenticated attackers
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 1
Frequently Asked Questions
What is CWE-23?
CWE-23 (CWE-23) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-23?
There are 488 CVE records associated with CWE-23 in our database. Of these, 57 are critical severity, 214 are high severity, and 173 are medium severity.
How can I protect against CWE-23 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-23 using AI-powered security agents.
Detect CWE-23 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-23 vulnerabilities across your infrastructure.
Get Started