CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
The Android application HTTP File Server (Version 1.4.1) by 'slowscript' is affected by a path traversal vulnerability t
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Eleme
htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php
A local file inclusion (LFI) vulnerability in D-Link DIR 819 v1.06 allows attackers to cause a Denial of Service (DoS) o
aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability th
Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via
Jenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and b
The Simple:Press plugin for WordPress is vulnerable to Path Traversal in versions up to, and including, 6.8 via the 'fil
Delta Industrial Automation DIALink versions prior to v1.5.0.0 Beta 4 uses an external input to construct a pathname int
Casdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.
Directory Traversal vulnerability in file cn/roothub/store/FileSystemStorageService in function store in Roothub 2.6.0 a
The AWS SDK for Java enables Java developers to work with Amazon Web Services. A partial-path traversal issue exists wit
Windows Print Spooler Elevation of Privilege Vulnerability
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lea
pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working direc
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior an
A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 m
In checkAccess of MediaProvider.java, there is a possible file deletion due to a path traversal error. This could lead t
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privil
Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevat
A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local
Huawei Aslan Children's Watch has a path traversal vulnerability. Successful exploitation may allow attackers to access
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of
Nimforum is a lightweight alternative to Discourse written in Nim. In versions prior to 2.2.0 any forum user can create
Argo CD before 2.1.9 and 2.2.x before 2.2.4 allows directory traversal related to Helm charts because of an error in hel
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may all
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.3.0 but before
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller v
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in cgi component in Synolog
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability
Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automa
MeterSphere is a one-stop open source continuous testing platform. Versions prior to 2.4.1 are vulnerable to Path Inject
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path tra
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module
Arbitrary file has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability .Successful exploitation o
HwPCAssistant has a Improper Input Validation vulnerability.Successful exploitation of this vulnerability may create any
An arbitrary file read vulnerability exists in NavigateCMS 2.9 via /navigate/navigate_download.php id parameter.
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511)
An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi
A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux versi
Platinum Upnp SDK through 1.2.0 has a directory traversal vulnerability. The attack could remote attack victim by sendin
This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of packa
An issue was discovered in FAUST iServer before 9.0.019.019.7. For each URL request, it accesses the corresponding .fau
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 al
Directory traversal vulnerability in TransmitMail 2.5.0 to 2.6.1 allows a remote unauthenticated attacker to obtain an a
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started