CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.
Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to do
ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection t
Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the l
Directory traversal vulnerability in page_edit.php in MiniCMS V1.10 allows remote attackers to read arbitrary files via
A directory traversal vulnerability in the Markdown engine of Gotenberg through 6.2.1 allows an attacker to read any con
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of sym
Local file inclusion in FHEM 6.0 allows in fhem/FileLog_logWrapper file parameter can allow an attacker to include a fil
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ESMPRO Man
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5
Directory traversal vulnerability in the yccms 3.3 project. The delete, deletesite, and deleteAll functions' improper ju
PacsOne Server (PACS Server In One Box) below 7.1.1 is affected by file read/manipulation, which can result in remote in
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and
Under specific circumstances SAP Master Data Management, versions - 710, 710.750, allows an unauthorized attacker to exp
Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to rea
The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to dow
Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow D
IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker co
Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenti
An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal
In Apache Ambari versions 2.6.2.2 and earlier, malicious users can construct file names for directory traversal and trav
A directory traversal on the /admin/sysmon.php script of Invigo Automatic Device Management (ADM) through 5.0 allows rem
A directory traversal on the /admin/search_by.php script of Invigo Automatic Device Management (ADM) through 5.0 allows
There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers
In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowe
ArcGIS GeoEvent Server versions 10.8.1 and below has a read-only directory path traversal vulnerability that could allow
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnera
Speco Web Viewer through 2021-05-12 allows Directory Traversal via GET request for a URI with /.. at the beginning, as d
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver
A local file inclusion vulnerability in the FileServlet in all SearchBlox before 9.2.2 allows remote, unauthenticated us
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in homeLYnk (Wiser F
LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Syno
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authen
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker
Path traversal vulnerability in share_link in QSAN Storage Manager allows remote attackers to download arbitrary files.
Path traversal vulnerability in QSAN Storage Manager allows remote unauthenticated attackers to download arbitrary files
Path traversal vulnerability in back-end analysis function in QSAN XEVO allows remote attackers to download arbitrary fi
Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly saniti
Specific page parameters in Dr. ID Door Access Control and Personnel Attendance Management system does not filter specia
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerabili
Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for
Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON file
This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it
In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter w
An issue in /admin/index.php?n=system&c=filept&a=doGetFileList of Metinfo v7.0.0 allows attackers to perform a directory
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started