Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-23 · Relative path traversalDefinition on MITRE ↗Clear

9 results

CVE-2026-34926
2026-05-21
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Trend Micro

Trend Micro Apex One (on-premise) contains a directory traversal vulnerability that could allow a pre-authenticated local attacker to modify a key table on the server to inject malicious code to deploy to agents on affected installations.

CWE-23 · Relative path traversal
Refssuccess.trendmicro.comnvd.nist.gov
Federal remediation due 2026-06-04
CVE-2024-27199
2026-04-20
JetBrains TeamCity Relative Path Traversal VulnerabilityRansomware
JetBrains

JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.

CWE-23 · Relative path traversal
Refsjetbrains.comblog.jetbrains.comnvd.nist.gov
Federal remediation due 2026-05-04
CVE-2025-64446
2025-11-14
Fortinet FortiWeb Path Traversal Vulnerability
Fortinet

Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.

CWE-23 · Relative path traversal
Refsfortiguard.comnvd.nist.gov
Federal remediation due 2025-11-21
CVE-2022-37042
2022-08-11
Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass VulnerabilityRansomware
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.

CWE-23 · Relative path traversal
Refsblog.zimbra.comnvd.nist.gov
Federal remediation due 2022-09-01
CVE-2021-38163
2022-06-09
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP

SAP NetWeaver contains a vulnerability that allows unrestricted file upload.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2022-06-30
CVE-2020-5410
2022-03-25
VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
VMware Tanzu / Spring Cloud Configuration (Config) Server

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2021-22017
2022-01-10
VMware vCenter Server Improper Access Control
VMware

Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2022-01-24
CVE-2021-22005
2021-11-03
VMware vCenter Server File Upload VulnerabilityRansomware
VMware

VMware vCenter Server contains a file upload vulnerability in the Analytics service that allows a user with network access to port 443 to execute code.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17
CVE-2021-21972
2021-11-03
VMware vCenter Server Remote Code Execution VulnerabilityRansomware
VMware

VMware vCenter Server vSphere Client contains a remote code execution vulnerability in a vCenter Server plugin which allows an attacker with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system.

CWE-23 · Relative path traversal
Refsnvd.nist.gov
Federal remediation due 2021-11-17