Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 149/161
7.5
CVE-2017-16135

serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16139

jikes is a file server. jikes is vulnerable to a directory traversal issue, giving an attacker access to the filesystem

7.5
CVE-2017-16140

lab6.brit95 is a file server. lab6.brit95 is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16141

lab6drewfusbyu is an http server. lab6drewfusbyu is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16142

infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16143

commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an

7.5
CVE-2017-16144

myserver.alexcthomas18 is a file server. myserver.alexcthomas18 is vulnerable to a directory traversal issue, giving an

7.5
CVE-2017-16145

sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker ac

7.5
CVE-2017-16146

mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the fil

7.5
CVE-2017-16147

shit-server is a file server. shit-server is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16148

serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16149

zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16150

wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker ac

7.5
CVE-2017-16152

static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an a

7.5
CVE-2017-16154

earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving a

7.5
CVE-2017-16155

fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directo

7.5
CVE-2017-16156

myprolyz is a static file server. myprolyz is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16157

censorify.tanisjr is a simple web server and API RESTful service. censorify.tanisjr is vulnerable to a directory travers

7.5
CVE-2017-16158

dcserver is a static file server. dcserver is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16159

caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16160

11xiaoli is a simple file server. 11xiaoli is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16161

shenliru is a simple file server. shenliru is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16162

22lixian is a simple file server. 22lixian is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16163

dylmomo is a simple file server. dylmomo is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16164

desafio is a simple web server. desafio is vulnerable to a directory traversal issue, giving an attacker access to the f

7.5
CVE-2017-16165

calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, g

7.5
CVE-2017-16166

byucslabsix is an http server. byucslabsix is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16167

yyooopack is a simple file server. yyooopack is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16168

wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t

7.5
CVE-2017-16169

looppake is a simple http server. looppake is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16170

liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16171

hcbserver is a static file server. hcbserver is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16172

section2.madisonjbrooks12 is a simple web server. section2.madisonjbrooks12 is vulnerable to a directory traversal issue

7.5
CVE-2017-16173

utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traver

7.5
CVE-2017-16174

whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16175

ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16176

jansenstuffpleasework is a file server. jansenstuffpleasework is vulnerable to a directory traversal issue, giving an at

7.5
CVE-2017-16177

chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16178

intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16180

serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16181

wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16182

serverxxx is a static file server. serverxxx is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16183

iter-server is a static file server. iter-server is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16184

scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory

7.5
CVE-2017-16185

uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker

7.5
CVE-2017-16186

360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an att

7.5
CVE-2017-16187

open-device creates a web interface for any device. open-device is vulnerable to a directory traversal issue, giving an

7.5
CVE-2017-16188

reecerver is a web server. reecerver is vulnerable to a directory traversal issue, giving an attacker access to the file

7.5
CVE-2017-16189

sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16190

dcdcdcdcdc is a static file server. dcdcdcdcdc is vulnerable to a directory traversal issue, giving an attacker access t

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started