Threats Tagged 'cwe-24'
View all threats tagged with 'cwe-24'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-24'
Click on any threat for detailed analysis and mitigation recommendations
XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request path. The affected lookup is replaced with Environment.getResourceAsStream(String, String), which constrains a resource to its expected prefix. An unauthenticated remote attacker can use the vulnerable behavior to read arbitrary resources permitted to the Jetty process, including WEB-INF/xwiki.cfg and, depending on deployment depth and operating-system permissions, host files. Tomcat and Jetty versions before 12 do not appear affected. This issue is fixed in versions 17.10.5 and 18.2.0. Join the discussion | CVE Database V5 | 09/14/2026, 17:12:18 UTC Added: 09/14/2026, 17:33:52 UTC |
Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file. Join the discussion | CVE Database V5 | 09/13/2026, 00:00:00 UTC Added: 09/13/2026, 19:17:48 UTC |
0 CVE-2026-14947 is a path traversal vulnerability in Frauscher Sensortechnik FDS 102 that allows a high-privileged remote attacker to upload a malicious ZIP archive containing directory traversal sequences (e.g., ../). This enables the attacker to escape the intended extraction directory and write files to arbitrary locations on the server. Improper validation of archive entry paths before writing files to disk can lead to arbitrary code execution and potentially full system compromise. The vulnerability affects versions from 2.8.0 up to and including 2.13.3. The CVSS 4.0 score is 8.6, indicating high severity. No patch or remediation details are provided in the input data. Join the discussion | CVE Database V5 | 08/20/2026, 08:18:49 UTC Added: 08/20/2026, 08:22:54 UTC |
In Zimbra Collaboration (ZCS) before 10.1.17, a path traversal vulnerability exists in the Zimbra Briefcase document editing functionality due to improper validation of the packages parameter. An authenticated attacker can exploit this vulnerability by supplying a crafted path traversal sequence, potentially allowing unauthorized disclosure of sensitive files within the web application directory. Join the discussion | CVE Database V5 | 08/13/2026, 15:22:21 UTC Added: 08/13/2026, 15:42:08 UTC |
XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, and 17.10.3, a potential path traversal vulnerability allow an attacker who manages to get a malicious WebJar extension installed on the wiki to write arbitrary files. While the consequences could be severe like overriding configuration files and setting the superadmin password, the attack first requires that the attacker already has admin access to at least a subwiki to be able to install a malicious extension. Further, the attacker needs to publish a malicious extension in an extension repository that is configured in the instance. This vulnerability has been patched in XWiki 16.10.17, 17.4.9, 17.10.3, and 18.0.0RC1. XWiki is not aware of any workarounds except for being careful whom developers grant script and admin rights to. Join the discussion | CVE Database V5 | 08/07/2026, 22:09:36 UTC Added: 08/07/2026, 22:26:59 UTC |
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content. Join the discussion | CVE Database V5 | 06/18/2026, 09:57:12 UTC Added: 06/18/2026, 10:51:31 UTC |
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows overwriting arbitrary files on disk. The OneNote converter does not sanitize the names of embedded files before writing them to disk. As a result, it's possible for an attacker to create a malicious .one file that includes file names containing ../../, that are then interpreted as part of the target path when extracting attachments from the .one file. This issue has been patched in version 3.5.7. Join the discussion | CVE Database V5 | 05/18/2026, 20:23:57 UTC Added: 05/18/2026, 20:51:39 UTC |
SiYuan is an open-source personal knowledge management system. In versions 3.6.3 and prior, the /api/av/removeUnusedAttributeView endpoint constructs a filesystem path using the user-controlled id parameter without validation or path boundary enforcement. An attacker can inject path traversal sequences such as ../ into the id value to escape the intended directory and delete arbitrary .json files on the server, including global configuration files and workspace metadata. This issue has been fixed in version 3.6.4. Join the discussion | CVE Database V5 | 04/16/2026, 22:54:47 UTC Added: 04/17/2026, 11:06:10 UTC |
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. Join the discussion | CVE Database V5 | 04/16/2026, 17:32:40 UTC Added: 04/16/2026, 18:01:52 UTC |
Path traversal vulnerability in the certificate management module. Impact: Successful exploitation of this vulnerability may affect availability. Join the discussion | CVE Database V5 | 03/05/2026, 07:51:00 UTC Added: 03/05/2026, 08:18:17 UTC |
Showing 1 to 10 of 23 results