CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Esri ArcGIS Server versions 10.9.1 and prior have a path traversal vulnerability that may result in a denial of service
Advantech R-SeeNet Versions 2.4.19 and prior are vulnerable to path traversal attacks. An unauthorized attacker could r
Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher.
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can e
Mail SQR Expert system has a Local File Inclusion vulnerability. An unauthenticated remote attacker can exploit this vul
When users add resources to the resource center with a relation path will cause path traversal issues and only for logge
UPSMON PRO’s has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerab
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation, arbitrary local files can be retri
Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.
Frappe version 14.10.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because th
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of t
A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lans
A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweep
Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to rea
nbnbk commit 879858451d53261d10f77d4709aee2d01c72c301 was discovered to contain an arbitrary file read vulnerability via
GetFile.aspx in Planet eStream before 6.72.10.07 allows ..\ directory traversal to read arbitrary local files.
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by auth
StreamX applications from versions 6.02.01 to 6.04.34 are affected by a path traversal vulnerability that allows authent
OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien
A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation lea
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated att
A vulnerability, which was classified as critical, has been found in lanyulei ferry. Affected by this issue is some unkn
Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue wh
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Elect
A vulnerability classified as critical was found in scifio. Affected by this vulnerability is the function downloadAndUn
A vulnerability, which was classified as critical, has been found in bspkrs MCPMappingViewer. Affected by this issue is
A vulnerability was found in jLEMS. It has been declared as critical. Affected by this vulnerability is the function unp
A vulnerability was found in drogatkin TJWS2. It has been declared as critical. Affected by this vulnerability is the fu
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allow
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some
An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controll
All versions of ETIC Telecom Remote Access Server (RAS) 4.5.0 and prior’s application programmable interface (API) is vu
In JetBrains IntelliJ IDEA before 2022.3 the built-in web server allowed an arbitrary file to be read by exploiting a pa
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccw
The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of fi
Sysaid – Sysaid Local File Inclusion (LFI) – An unauthenticated attacker can access to the system by accessing to "/lib/
Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability
The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function,
Mendelson OFTP2 before 1.1 b43 is affected by directory traversal. To access the vulnerable code path, the attacker has
Uncontrolled search path element vulnerability in Samsung Update prior to version 3.0.77.0 allows attackers to execute a
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user als
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file operation managemen
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file wr
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to 0.1.5 are vulnerable to Relative Path Trav
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to
Pandora FMS v7.0NG.760 and below allows a relative path traversal in File Manager where a privileged user could upload a
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started