CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
An issue in the component BlogEngine/BlogEngine.NET/AppCode/Api/UploadController.cs of BlogEngine.NET v3.3.8.0 allows at
An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can u
CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneD
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial version
Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potential
Dell GeoDrive, Versions 1.0 - 2.2, contain a Path Traversal Vulnerability in the reporting function. A local, low privil
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat
Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a ser
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Server since 4.3.0 can result in arb
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allow
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGI
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Ex
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver
Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
In BIG-IP Versions 16.1.x before 16.1.1 and 15.1.x before 15.1.4, when running in Appliance mode, an authenticated attac
Auth. Path Traversal vulnerability in Easy WP SMTP plugin <= 1.5.1 on WordPress.
IBM Spectrum Scale 5.1 could allow users with permissions to create pod, persistent volume and persistent volume claim
Tauri is a framework for building binaries for all major desktop platforms. The filesystem glob pattern wildcards `*`, `
Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before versio
In openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lea
Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in
The All-in-One WP Migration plugin for WordPress is vulnerable to arbitrary file deletion via directory traversal due to
An information exposure issue has been discovered in Opmantek Open-AudIT 4.2.0. The vulnerability allows an authenticate
CoreFTP Server before 727 allows directory traversal (for file creation) by an authenticated attacker via ../ in an HTTP
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers
This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the ser
ASUS RT-AX56U’s login function contains a path traversal vulnerability due to its inadequate filtering for special chara
Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not ha
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in support service manageme
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier does not restrict the names of resources
A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory trave
A Path Traversal vulnerability for a log file in LiveConfig 2.12.2 allows authenticated attackers to read files on the u
Path Traversal in GitHub repository pimcore/pimcore prior to 10.3.2.
There is a directory traversal vulnerability in some home gateway products of ZTE. Due to the lack of verification of us
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via
The Cost Calculator WordPress plugin through 1.6 allows authenticated users (Contributor+ in versions < 1.5, and Admin+
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfS
NATS nats-server before 2.7.4 allows Directory Traversal (with write access) via an element in a ZIP archive for JetStre
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any
Jenkins Extended Choice Parameter Plugin 346.vd87693c5a_86c and earlier allows attackers with Item/Configure permission
Jenkins Kubernetes Continuous Deploy Plugin 2.3.1 and earlier allows users with Credentials/Create permission to read ar
A malicious, but authorised and authenticated user can construct an HTTP request using their existing CSRF token and ses
aaPanel v6.8.21 was discovered to be vulnerable to directory traversal. This vulnerability allows attackers to obtain th
Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier allows attackers with Item/Configure permission to
The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to fil
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started