CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file s
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remot
An issue was discovered in Mattermost Mobile Apps before 1.26.0. An attacker can use directory traversal with the Video
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
Bludit v3.8.1 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /admin/ajax/up
GetSimpleCMS-3.3.15 is affected by directory traversal. Remote attackers are able to delete arbitrary files via /GetSimp
A command injection vulnerability was discovered in Gitlab runner versions prior to 13.2.4, 13.3.2 and 13.4.1. When the
A path handling issue was addressed with improved validation. This issue is fixed in iOS 13.6 and iPadOS 13.6, macOS Cat
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, allows an authenticated user to upload a malicious
An issue was discovered in the mozwire crate through 2020-08-18 for Rust. A ../ directory-traversal situation allows ove
A vulnerability has been reported to affect earlier QNAP devices running QTS 4.3.4 to 4.3.6. Caused by improper limitati
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated us
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attack
Lotus Core CMS 1.0.1 allows authenticated Local File Inclusion of .php files via directory traversal in the index.php pa
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code
SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31
IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a r
TeamPass 2.1.27.36 allows any authenticated TeamPass user to trigger a PHP file include vulnerability via a crafted HTTP
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authentic
Advantech WebAccess Node, Version 8.4.4 and prior, Version 9.0.0. Multiple relative path traversal vulnerabilities exist
The DataEngine Xnode Server application in Zoho ManageEngine DataSecurity Plus prior to 6.0.1 does not validate the data
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages incl
MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is usin
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed wi
A vulnerability in the web management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote at
OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files
A vulnerability in the archive utility of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Librar
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Marvell QConvergeConso
A remote code execution vulnerability in Mitel MiVoice Connect Client before 214.100.1223.0 could allow an attacker to e
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory trav
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory trav
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory trav
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory trav
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory trav
An issue was discovered in Observium Professional, Enterprise & Community 20.8.10631. It is vulnerable to directory trav
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started