CWE-41

Total CVEs
18
Vulnerabilities
Avg CVSS v3
5.9
Medium
Avg CVSS v2
5.8
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 0
0%
High 6
33.3%
Medium 12
66.7%
Low 0
0%

External References

All CVEs (18)

Page 1 of 1
CVSS:8.6(High)

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve ...

CWE-412025
CVSS:7.8(High)

Windows Security Zone Mapping Security Feature Bypass Vulnerability

CWE-412024
CVSS:7.8(High)

Windows Compressed Folder Remote Code Execution Vulnerability

CWE-412023
CVSS:7.4(High)

Improper Resolution of Path Equivalence in GitHub repository microweber-dev/whmcs_plugin prior to 0.0.4.

CWE-412022
CVSS:7.3(High)

In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. Thi...

CWE-412024
CVSS:6.5(Medium)

Windows Deployment Services Information Disclosure Vulnerability

CWE-412024
CVSS:6.5(Medium)

IBM DS8900F HMC 89.21.19.0, 89.21.31.0, 89.30.68.0, 89.32.40.0, and 89.33.48.0 could allow an authenticated user to arbitrarily delete a file. IBM X-Force ID: 269406.

CWE-412023
CVSS:6.0(Medium)

`gix-path` is a crate of the `gitoxide` project (an implementation of `git` written in Rust) dealing paths and their conversions. Prior to version 0.10.11, `gix-path` runs `git` to find the path of a ...

CWE-412024
CVSS:4.3(Medium)

Windows HTML Platforms Security Feature Bypass Vulnerability

CWE-412025
CVSS:4.3(Medium)

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

CWE-412025
CVSS:4.3(Medium)

corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to...

CWE-412024

A vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated admin on the PAN-OS CLI to read arbitrary files. The attacker must have network access to the management interface (w...

CWE-412025