CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit
In Lavalite 9.0.0, the XSRF-TOKEN cookie is vulnerable to path traversal attacks, enabling read access to arbitrary file
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow
A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Adva
A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows
In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path trave
When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated remote attacker can exploit
A Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 be
Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through
The Netic User Export add-on before 1.3.5 for Atlassian Confluence has the functionality to generate a list of users in
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allow
In s::can moni::tools in versions below 4.2 an unauthenticated attacker could get any file from the device by path trave
Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download
Red Lion Controls Crimson 3.0 versions 707.000 and prior, Crimson 3.1 versions 3126.001 and prior, and Crimson 3.2 versi
Unauth. Directory Traversal vulnerability in Welcart eCommerce plugin <= 2.7.7 on WordPress.
A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker c
FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request.
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are
On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide
A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attacke
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
AeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component
All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and s
The multi-screen collaboration module has a path traversal vulnerability. Successful exploitation of this vulnerability
The backup module has a path traversal vulnerability. Successful exploitation of this vulnerability causes unauthorized
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sand
AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an
An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web
Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read
Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to re
There is a path traversal vulnerability in Esri ArcGIS Server versions 10.9.1 and below. Successful exploitation may all
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a logic bug that allows to bypass the implemented
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions a
MeterSphere is a one-stop open source continuous testing platform, covering test management, interface testing, UI testi
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` m
Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability
Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write a
Improper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an a
AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts file
DSpace open source software is a repository application which provides durable access to digital resources. In affected
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vu
Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administ
The WPIDE WordPress plugin before 3.0 does not sanitize and validate the filename parameter before using it in a require
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in upload
The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the conf
Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started