CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
qrcp through 0.8.4, in receive mode, allows ../ Directory Traversal via the file name specified by the uploader.
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) AgentDaServlet has directory travers
An issue in index.php of OneNav v0.9.14 allows attackers to perform directory traversal.
The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.
The JobMonster Theme was vulnerable to Directory Listing in the /wp-content/uploads/jobmonster/ folder, as it did not in
A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Applia
Shopwind <=v3.4.2 was discovered to contain a Arbitrary File Download vulnerability via the neirong parameter at \backen
### Impact A plugin public script can be used to read content of system files. ### Patches Upgrade to version 1.0.2. ###
An issue has been discovered in GitLab EE affecting all versions starting from 12.5 before 15.0.5, all versions starting
Improper access control and path traversal vulnerability in LauncherProvider prior to SMR Aug-2022 Release 1 allow local
This affects the package com.diffplug.gradle:goomph before 3.37.2. It allows a malicious zip file to potentially break o
An absolute path traversal vulnerability in ZZCMS 2022 allows attackers to obtain sensitive information via a crafted GE
ZZCMS 2022 was discovered to contain a full path disclosure vulnerability via the page /admin/index.PHP? _server.
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hos
Webvendome - webvendome Internal Server IP Disclosure. Send GET Request to the request which is shown in the picture. I
qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allow
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing
Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via c
A vulnerability has been found in RainyGao DocSys and classified as critical. Affected by this vulnerability is an unkno
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function Resource
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, al
The OMGF | Host Google Fonts Locally WordPress plugin before 4.5.12 does not validate the cache directory setting, allow
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in
The Contact Forms - Drag & Drop Contact Form Builder WordPress plugin through 1.0.5 allows high privilege users to downl
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2 Patch 600 and 8.x before 8.0.0 Patch
The String locator WordPress plugin before 2.5.0 does not properly validate the path of the files to be searched, allowi
An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.
A post-authentication arbitrary file read vulnerability impacting end-of-life Secure Remote Access (SRA) products and ol
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabli
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially expl
This affects the package snyk-broker before 4.73.0. It allows arbitrary file reads for users with access to Snyk's inter
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary file reading in versions
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Directory Traversal in versions up
The Migration, Backup, Staging WordPress plugin before 0.9.76 does not sanitise and validate a parameter before using it
The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privil
Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.
The Enable Media Replace WordPress plugin before 4.0.0 does not ensure that renamed files are moved to the Upload folder
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a
Due to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with hi
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified throu
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful explo
An authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Success
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the pa
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which c
A vulnerability classified as critical has been found in RainyGao DocSys 2.02.37. This affects an unknown part of the co
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started