CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Jenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any
SYNEL - eharmony Directory Traversal. Directory Traversal - is an attack against a server or a Web application aimed at
The package juce-framework/juce before 6.1.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) vi
"Sametime Android PathTraversal Vulnerability"
"Sametime Android potential path traversal vulnerability when using File class"
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
In aee daemon, there is a possible information disclosure due to a path traversal. This could lead to local information
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in GiveWP's GiveWP plugin <= 2.
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
A vulnerability in Brocade Fabric OS versions 7.4.1b and 7.3.1d could allow local users to conduct privileged directory
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative p
A vulnerability was found in networkd-dispatcher. This flaw exists because no functions are sanitized by the Operational
A vulnerability in the CLI of stand-alone Cisco IOS XE SD-WAN Software and Cisco SD-WAN Software could allow an authenti
In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allo
In update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error.
A vulnerability has been found in MZ Automation libiec61850 up to 1.4 and classified as critical. This vulnerability aff
A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this v
A directory traversal vulnerability in the ZIP archive extraction routines of KNIME Analytics Platform 3.2.0 and above c
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a z
A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the fi
A vulnerability classified as critical was found in SimbCo httpster. This vulnerability affects the function fs.realpath
A vulnerability was found in FlatPress. It has been classified as critical. This affects the function doItemActions of t
Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and be
A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
A vulnerability, which was classified as problematic, has been found in UBI Reader up to 0.8.0. Affected by this issue i
Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted
The CaasKit module has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the MeeTi
HwPCAssistant has a path traversal vulnerability. Successful exploitation of this vulnerability may affect data confiden
ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
Apache Karaf obr:* commands and run goal on the karaf-maven-plugin have partial path traversal which allows to break out
Directory traversal in /northstar/Common/NorthFileManager/fileManagerObjects.jsp Northstar Technologies Inc NorthStar Cl
Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top
A ..%2F path traversal vulnerability exists in the path handler of awful-salmonella-tar before 0.0.4. Attackers can only
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started