CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Improper Access Control in Jfinal CMS v4.7.1 and earlier allows remote attackers to obtain sensitive information via the
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), wh
Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal
Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enu
Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data
An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affe
The file browser in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier may interpret some paths to files as absolute on
Projectsend version r1295 is affected by a directory traversal vulnerability. A user with Uploader role can add value `2
rConfig 3.9.6 is affected by a Local File Disclosure vulnerability. An authenticated user may successfully download any
A remote unauthorized read access to files vulnerability was discovered in Aruba Instant version(s): 6.4.x.x: 6.4.4.8-4.
Directory traversal vulnerability in the management screen of Cybozu Remote Service 3.1.8 allows a remote authenticated
The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path trave
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
An issue in the FTP server of Sky File v2.1.0 allows attackers to perform directory traversal via `/null//` path command
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li
There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special char
A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V
TwinCAT OPC UA Server in TF6100 and TS6100 in product versions before 4.3.48.0 or with TcOpcUaServer versions below 3.2.
bookstack is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an att
OX App Suite through 7.10.5 allows Directory Traversal via ../ in an OOXML or ODF ZIP archive, because of the mishandlin
There is a Improper Access Control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will
A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading f
A directory traversal vulnerability exists in the Web Manager FsBrowseClean functionality of Lantronix PremierWave 2050
Specially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attemp
ftp-srv is an open-source FTP server designed to be simple yet configurable. In ftp-srv before version 4.4.0 there is a
An improper validation vulnerability in FilterProvider prior to SMR Dec-2021 Release 1 allows attackers to write arbitra
A local path traversal vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Softwa
Quagga Services on D-Link DIR-2640 less than or equal to version 1.11B02 are affected by an absolute path traversal vuln
This vulnerability allows local attackers to delete arbitrary files on affected installations of Parallels Desktop 16.1.
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker
Improper URL validation in development mode handler in com.vaadin:flow-server versions 2.0.0 through 2.4.1 (Vaadin 14.0.
A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows rem
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassP
Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server whe
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or a
in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected v
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Dir
When loading a UDF, a specially crafted zip file could allow files to be placed outside of the UDF deployment directory.
An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files
The Backup functionality in Grav CMS through 1.7.0-rc.17 allows an authenticated attacker to read arbitrary local files
A vulnerability in all versions of Kuba allows attackers to overwrite arbitrary files in arbitrary directories with craf
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in S
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in S
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
An improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows at
A vulnerability in the debug shell of Cisco IP Phone software could allow an authenticated, local attacker to read any f
Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to lo
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started