CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
serverzyy is a static file server. serverzyy is vulnerable to a directory traversal issue, giving an attacker access to
jikes is a file server. jikes is vulnerable to a directory traversal issue, giving an attacker access to the filesystem
lab6.brit95 is a file server. lab6.brit95 is vulnerable to a directory traversal issue, giving an attacker access to the
lab6drewfusbyu is an http server. lab6drewfusbyu is vulnerable to a directory traversal issue, giving an attacker access
infraserver is a RESTful server. infraserver is vulnerable to a directory traversal issue, giving an attacker access to
commentapp.stetsonwood is an http server. commentapp.stetsonwood is vulnerable to a directory traversal issue, giving an
myserver.alexcthomas18 is a file server. myserver.alexcthomas18 is vulnerable to a directory traversal issue, giving an
sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker ac
mockserve is a file server. mockserve is vulnerable to a directory traversal issue, giving an attacker access to the fil
shit-server is a file server. shit-server is vulnerable to a directory traversal issue, giving an attacker access to the
serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the
zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to th
wanggoujing123 is a simple webserver. wanggoujing123 is vulnerable to a directory traversal issue, giving an attacker ac
static-html-server is a static file server. static-html-server is vulnerable to a directory traversal issue, giving an a
earlybird is a web server module for early development. earlybird is vulnerable to a directory traversal issue, giving a
fast-http-cli is the command line interface for fast-http, a simple web server. fast-http-cli is vulnerable to a directo
myprolyz is a static file server. myprolyz is vulnerable to a directory traversal issue, giving an attacker access to th
censorify.tanisjr is a simple web server and API RESTful service. censorify.tanisjr is vulnerable to a directory travers
dcserver is a static file server. dcserver is vulnerable to a directory traversal issue, giving an attacker access to th
caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access
11xiaoli is a simple file server. 11xiaoli is vulnerable to a directory traversal issue, giving an attacker access to th
shenliru is a simple file server. shenliru is vulnerable to a directory traversal issue, giving an attacker access to th
22lixian is a simple file server. 22lixian is vulnerable to a directory traversal issue, giving an attacker access to th
dylmomo is a simple file server. dylmomo is vulnerable to a directory traversal issue, giving an attacker access to the
desafio is a simple web server. desafio is vulnerable to a directory traversal issue, giving an attacker access to the f
calmquist.static-server is a static file server. calmquist.static-server is vulnerable to a directory traversal issue, g
byucslabsix is an http server. byucslabsix is vulnerable to a directory traversal issue, giving an attacker access to th
yyooopack is a simple file server. yyooopack is vulnerable to a directory traversal issue, giving an attacker access to
wffserve is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t
looppake is a simple http server. looppake is vulnerable to a directory traversal issue, giving an attacker access to th
liuyaserver is a static file server. liuyaserver is vulnerable to a directory traversal issue, giving an attacker access
hcbserver is a static file server. hcbserver is vulnerable to a directory traversal issue, giving an attacker access to
section2.madisonjbrooks12 is a simple web server. section2.madisonjbrooks12 is vulnerable to a directory traversal issue
utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traver
whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the
ewgaddis.lab6 is a file server. ewgaddis.lab6 is vulnerable to a directory traversal issue, giving an attacker access to
jansenstuffpleasework is a file server. jansenstuffpleasework is vulnerable to a directory traversal issue, giving an at
chatbyvista is a file server. chatbyvista is vulnerable to a directory traversal issue, giving an attacker access to the
intsol-package is a file server. intsol-package is vulnerable to a directory traversal issue, giving an attacker access
serverabc is a static file server. serverabc is vulnerable to a directory traversal issue, giving an attacker access to
wintiwebdev is a static file server. wintiwebdev is vulnerable to a directory traversal issue, giving an attacker access
serverxxx is a static file server. serverxxx is vulnerable to a directory traversal issue, giving an attacker access to
iter-server is a static file server. iter-server is vulnerable to a directory traversal issue, giving an attacker access
scott-blanch-weather-app is a sample Node.js app using Express 4. scott-blanch-weather-app is vulnerable to a directory
uekw1511server is a static file server. uekw1511server is vulnerable to a directory traversal issue, giving an attacker
360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an att
open-device creates a web interface for any device. open-device is vulnerable to a directory traversal issue, giving an
reecerver is a web server. reecerver is vulnerable to a directory traversal issue, giving an attacker access to the file
sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the
dcdcdcdcdc is a static file server. dcdcdcdcdc is vulnerable to a directory traversal issue, giving an attacker access t
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started