Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 150/161
7.5
CVE-2017-16191

cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16192

getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attac

7.5
CVE-2017-16193

mfrs is a static file server. mfrs is vulnerable to a directory traversal issue, giving an attacker access to the filesy

7.5
CVE-2017-16194

picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the files

7.5
CVE-2017-16195

pytservce is a static file server. pytservce is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16196

quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker

7.5
CVE-2017-16197

qinserve is a static file server. qinserve is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16198

ritp is a static web server. ritp is vulnerable to a directory traversal issue whereby an attacker can gain access to th

7.5
CVE-2017-16199

susu-sum is a static file server. susu-sum is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16200

uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access t

7.5
CVE-2017-16201

zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16208

dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16209

enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the

7.5
CVE-2017-16210

jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker acce

7.5
CVE-2017-16211

lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16212

ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst

7.5
CVE-2017-16213

mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16214

peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2017-16215

sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to th

7.5
CVE-2017-16216

tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker a

7.5
CVE-2017-16217

fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue

7.5
CVE-2017-16218

dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access

7.5
CVE-2017-16219

yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the fi

7.5
CVE-2017-16220

wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the fi

7.5
CVE-2017-16221

yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst

7.5
CVE-2017-16223

nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to

7.5
CVE-2018-3724

general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which

7.5
CVE-2018-3725

hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a maliciou

7.5
CVE-2018-3727

626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious

7.5
CVE-2018-3729

localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a

7.5
CVE-2018-3730

mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a m

7.5
CVE-2018-3731

public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a mal

7.5
CVE-2018-3732

resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths wit

7.5
CVE-2018-0296 KEV

A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo

7.5
CVE-2018-12042

Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.

7.5
CVE-2018-12053

Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p

7.5
CVE-2018-12054

Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol

7.5
CVE-2017-5381

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif

7.5
CVE-2018-0496

Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / Proton

7.5
CVE-2017-17309

Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received

7.5
CVE-2018-8727

Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system

7.5
CVE-2018-12631

Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/tex

7.5
CVE-2018-10956

IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.

7.5
CVE-2018-3760

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12

7.5
CVE-2018-12909

Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the we

7.5
CVE-2018-11051

RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA C

7.5
CVE-2018-3766

Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.

7.5
CVE-2018-11543

A Local File Inclusion (LFI) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the

7.5
CVE-2018-6830

Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V

7.5
CVE-2013-3001

Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to r

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started