CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
The create_response function in server/server.c in Psensor before 1.1.4 allows Directory Traversal because it lacks a ch
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress al
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versio
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the c
The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, ev
gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url
stattic node module suffers from a Path Traversal vulnerability due to lack of validation of path, which allows a malici
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacke
hostr is a simple web server that serves up the contents of the current directory. There is a directory traversal vulner
`badjs-sourcemap-server` receives files sent by `badjs-sourcemap`. `badjs-sourcemap-server` is vulnerable to a directory
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by
`f2e-server` 1.12.11 and earlier is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, g
list-n-stream is a server for static files to list and stream local videos. list-n-stream v0.0.10 or lower is vulnerable
tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacke
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to
fsk-server is a simple http server. fsk-server is vulnerable to a directory traversal issue, giving an attacker access t
xtalk helps your browser talk to nodex, a simple web framework. xtalk is vulnerable to a directory traversal issue, givi
Sencisho is a simple http server for local development. Sencisho is vulnerable to a directory traversal issue, giving an
cyber-js is a simple http server. A cyberjs server is vulnerable to a directory traversal issue, giving an attacker acce
iter-http is a server for static files. iter-http is vulnerable to a directory traversal issue, giving an attacker acces
serverliujiayi1 is a simple http server. serverliujiayi1 is vulnerable to a directory traversal issue, giving an attacke
serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker
tiny-http is a simple http server. tiny-http is vulnerable to a directory traversal issue, giving an attacker access to
serverwg is a simple http server. serverwg is vulnerable to a directory traversal issue, giving an attacker access to th
serverhuwenhui is a simple http server. serverhuwenhui is vulnerable to a directory traversal issue, giving an attacker
serveryztyzt is a simple http server. serveryztyzt is vulnerable to a directory traversal issue, giving an attacker acce
citypredict.whauwiller is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by plac
serverwzl is a simple http server. serverwzl is vulnerable to a directory traversal issue, giving an attacker access to
tmock is a static file server. tmock is vulnerable to a directory traversal issue, giving an attacker access to the file
pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "..
gaoxiaotingtingting is an HTTP server. gaoxiaotingtingting is vulnerable to a directory traversal issue, giving an attac
weather.swlyons is a simple web server for weather updates. weather.swlyons is vulnerable to a directory traversal issue
liyujing is a static file server. liyujing is vulnerable to a directory traversal issue, giving an attacker access to th
datachannel-client is a signaling implementation for DataChannel.js. datachannel-client is vulnerable to a directory tra
cuciuci is a simple fileserver. cuciuci is vulnerable to a directory traversal issue, giving an attacker access to the f
welcomyzt is a simple file server. welcomyzt is vulnerable to a directory traversal issue, giving an attacker access to
node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue,
rtcmulticonnection-client is a signaling implementation for RTCMultiConnection.js, a multi-session manager. rtcmulticonn
exxxxxxxxxxx is an Http eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issu
unicorn-list is a web framework. unicorn-list is vulnerable to a directory traversal issue, giving an attacker access to
simple-npm-registry is a local npm package cache. simple-npm-registry is vulnerable to a directory traversal issue, givi
goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
http_static_simple is an http server. http_static_simple is vulnerable to a directory traversal issue, giving an attacke
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started