Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 148/161
7.5
CVE-2014-10073

The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a ch

7.5
CVE-2018-7669

An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application

7.5
CVE-2017-18263

Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via

7.5
CVE-2015-1503

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary

7.5
CVE-2018-0588

Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress al

7.5
CVE-2018-7495

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio

7.5
CVE-2018-7503

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio

7.5
CVE-2018-11319

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the c

7.5
CVE-2014-10068

The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, ev

7.5
CVE-2017-16153

gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t

7.5
CVE-2018-3733

crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url

7.5
CVE-2018-3734

stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malici

7.5
CVE-2014-10066

Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke

7.5
CVE-2017-16029

hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulner

7.5
CVE-2017-16036

`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory

7.5
CVE-2017-16037

`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by

7.5
CVE-2017-16038

`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesyst

7.5
CVE-2017-16039

`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16083

node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, g

7.5
CVE-2017-16084

list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable

7.5
CVE-2017-16085

tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacke

7.5
CVE-2017-16089

serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16090

fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access t

7.5
CVE-2017-16091

xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, givi

7.5
CVE-2017-16092

Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an

7.5
CVE-2017-16093

cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker acce

7.5
CVE-2017-16094

iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker acces

7.5
CVE-2017-16095

serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacke

7.5
CVE-2017-16096

serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker

7.5
CVE-2017-16097

tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16101

serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16102

serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker

7.5
CVE-2017-16103

serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker acce

7.5
CVE-2017-16104

citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plac

7.5
CVE-2017-16105

serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16106

tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the file

7.5
CVE-2017-16107

pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "..

7.5
CVE-2017-16108

gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attac

7.5
CVE-2017-16110

weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue

7.5
CVE-2017-16120

liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16121

datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory tra

7.5
CVE-2017-16122

cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the f

7.5
CVE-2017-16123

welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16124

node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue,

7.5
CVE-2017-16125

rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonn

7.5
CVE-2017-16130

exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issu

7.5
CVE-2017-16131

unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16132

simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, givi

7.5
CVE-2017-16133

goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesyst

7.5
CVE-2017-16134

http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacke

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started