CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_fi
The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send
The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the
The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Fla
The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file func
The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the
The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Fla
The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file fun
The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file func
The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function
The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask sen
The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file fun
The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_fil
The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask se
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask
The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Fl
The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask se
The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal be
The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send
The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file func
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file f
The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_fi
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_fi
The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask se
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file fun
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_fi
The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file f
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file functi
The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file f
The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because
The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_fil
The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask sen
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask
The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask sen
The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flas
The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the F
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_fil
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flas
The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file fu
The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_fi
The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because t
The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_fil
The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Fla
The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because t
The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Fl
The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_f
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started