CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, rem
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could a
Local file inclusion in Pyrescom Termod4 time management devices before 10.04k allows authenticated remote attackers to
IBM QRadar SIEM 7.4.2 GA to 7.4.2 Patch 1, 7.4.0 to 7.4.1 Patch 1, and 7.3.0 to 7.3.3 Patch 5 could allow a remote attac
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distri
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Ori
Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware a
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the sys
spxmanage on certain SpinetiX devices allows requests that access unintended resources because of SSRF and Path Traversa
A vulnerability in the Cisco IOx application hosting environment of multiple Cisco platforms could allow an authenticate
Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is
A path traversal vulnerability in the Juniper Networks SRX and vSRX Series may allow an authenticated J-web user to read
Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administra
A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco Ro
Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user
A Directory Traversal vulnerability exists in FusionPBX 4.5.7 allows malicoius users to rename any file of the system.vi
An arbitrary file deletion vulnerability was discovered on htmly v2.7.5 which allows remote attackers to use any absolut
IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or c
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Ba
BloofoxCMS 0.5.2.1 allows Directory traversal vulnerability by inserting '../' payloads within the 'fileurl' parameter.
Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may
Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker t
Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download
Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers down
A Directory Traversal vulnerability in the Unzip feature in Elements-IT HTTP Commander 5.3.3 allows remote authenticated
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an auth
In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the
NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading
A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to o
Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter
The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unautho
A directory traversal issue in KiteCMS 1.1.1 allows remote administrators to overwrite arbitrary files via ../ in the pa
The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a mal
Directory Traversal vulnerability exists in PopojiCMS 2.0.1 via the id parameter in admin.php.
An issue in the /config/config.php component of Indexhibit 2.1.5 allows attackers to arbitrarily view files.
A remote path traversal vulnerability was discovered in Aruba Operating System Software version(s): Prior to 8.8.0.1, 8.
A remote path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Softw
SAP Business One version - 10.0 allows low-level authorized attacker to traverse the file system to access files or dire
On BIG-IP, on all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a directory traversal vulnerab
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive infromation via the
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started