CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Bookeen Notea Firmware BK_R_1.0.5_20210608 is affected by a directory traversal vulnerability that allows an attacker to
Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source c
A vulnerability was found in Widoco and classified as critical. Affected by this issue is the function unZipIt of the fi
A Directory Traversal vulnerability exists in S-Cart 6.7 via download in sc-admin/backup.
A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functiona
In writeApplicationRestrictionsLAr of UserManagerService.java, there is a possible overwrite of system files due to a pa
Jenkins Publish Over SSH Plugin 1.22 and earlier performs a validation of the file name specifying whether it is present
Fix of CVE-2021-40525 do not prepend delimiters upon valid directory validations. Affected implementations include: - ma
Jenkins Fortify Plugin 20.2.34 and earlier does not sanitize the appName and appVersion parameters of its Pipeline steps
IBM Sterling External Authentication Server 3.4.3.2, 6.0.2.0, and 6.0.3.0 is vulnerable to path traversals, due to not p
Passwork On-Premise Edition before 4.6.13 allows migration/downloadExportFile Directory Traversal (to read files).
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Uni
Jenkins Deployer Framework Plugin 85.v1d1888e8c021 and earlier does not restrict the name of files in methods implementi
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the v
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classl
A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to u
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SU
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUS
A vulnerability, which was classified as critical, has been found in Ultimate Member Plugin up to 2.5.0. This issue affe
The Ultimate Member plugin for WordPress is vulnerable to directory traversal in versions up to, and including 2.5.0 due
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files the
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a che
SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a che
Path traversal vulnerability in Samsung Flow prior to version 4.8.07.4 allows local attackers to read arbitrary files as
Path traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arb
Improper input validation in Contacts Storage prior to SMR Jul-2022 Release 1 allows attacker to access arbitrary file.
Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary fi
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename'
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-leve
A vulnerability in the Localdisk Management feature of Cisco Identity Services Engine (ISE) could allow an authenticated
The Simple:Press plugin for WordPress is vulnerable to arbitrary file modifications in versions up to, and including, 6.
A vulnerability, which was classified as problematic, was found in lanyulei ferry. This affects an unknown part of the f
A vulnerability was found in pastebinit up to 0.2.2 and classified as problematic. Affected by this issue is the functio
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SafeNet KeySecure allows
In Amanda 3.5.1, an information leak vulnerability was found in the calcsize SUID binary. An attacker can abuse this vul
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path
Nextcloud android is the official Android client for the Nextcloud home server platform. Internal paths to the Nextcloud
A vulnerability, which was classified as problematic, was found in aerouk imageserve. Affected is an unknown function of
ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
Arbitrary File Read vulnerability in WPvivid Team Migration, Backup, Staging – WPvivid (WordPress plugin) versions <= 0.
A highly privileged remote attacker, can gain unauthorized access to display contents of restricted directories by explo
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with v
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
Directory traversal vulnerability in EC-CUBE 3 series (EC-CUBE 3.0.0 to 3.0.18-p4 ) and EC-CUBE 4 series (EC-CUBE 4.0.0
FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicaliz
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulne
NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability was discovered via an HTTP
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started