CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special c
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stac
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters u
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier,
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with t
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server
Alist v3.4.0 is vulnerable to Directory Traversal,
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, a
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allo
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is en
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentConfigurationServlet has direct
The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_f
The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_fil
The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file fun
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because
The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask se
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_fi
The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file funct
The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file fu
The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_fi
The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send
The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_fi
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file
The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file
The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask s
The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file functi
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file f
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path tra
The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file fun
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the F
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file f
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file fu
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask
The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function
The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send
The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask se
The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal becaus
The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send
The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is
The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file functi
The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask sen
The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_f
The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started