A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttr
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privilege
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior
fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including
OpenDeck is Linux software for your Elgato Stream Deck. Prior to 2.8.1, the service listening on port 57118 serves stati
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../
REDAXO is a PHP-based content management system. Prior to version 5.20.2, authenticated users with backup permissions ca
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the POS
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability
Fonoster 0.5.5 before 0.6.1 allows ../ directory traversal to read arbitrary files via the /sounds/:file or /tts/:file V
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape th
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document edi
Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. Thi
Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-t
XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to
Frequently Asked Questions
What is CWE-24?
CWE-24 (CWE-24) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-24?
There are 20 CVE records associated with CWE-24 in our database. Of these, 1 are critical severity, 7 are high severity, and 7 are medium severity.
How can I protect against CWE-24 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-24 using AI-powered security agents.
Detect CWE-24 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-24 vulnerabilities across your infrastructure.
Get Started