CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
cypserver is a static file server. cypserver is vulnerable to a directory traversal issue, giving an attacker access to
getcityapi.yoehoehne is a web server. getcityapi.yoehoehne is vulnerable to a directory traversal issue, giving an attac
mfrs is a static file server. mfrs is vulnerable to a directory traversal issue, giving an attacker access to the filesy
picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the files
pytservce is a static file server. pytservce is vulnerable to a directory traversal issue, giving an attacker access to
quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker
qinserve is a static file server. qinserve is vulnerable to a directory traversal issue, giving an attacker access to th
ritp is a static web server. ritp is vulnerable to a directory traversal issue whereby an attacker can gain access to th
susu-sum is a static file server. susu-sum is vulnerable to a directory traversal issue, giving an attacker access to th
uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access t
zjjserver is a static file server. zjjserver is vulnerable to a directory traversal issue, giving an attacker access to
dmmcquay.lab6 is a REST server. dmmcquay.lab6 is vulnerable to a directory traversal issue, giving an attacker access to
enserver is a simple web server. enserver is vulnerable to a directory traversal issue, giving an attacker access to the
jn_jj_server is a static file server. jn_jj_server is vulnerable to a directory traversal issue, giving an attacker acce
lessindex is a static file server. lessindex is vulnerable to a directory traversal issue, giving an attacker access to
ltt is a static file server. ltt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
mfrserver is a simple file server. mfrserver is vulnerable to a directory traversal issue, giving an attacker access to
peiserver is a static file server. peiserver is vulnerable to a directory traversal issue, giving an attacker access to
sgqserve is a simple file server. sgqserve is vulnerable to a directory traversal issue, giving an attacker access to th
tencent-server is a simple web server. tencent-server is vulnerable to a directory traversal issue, giving an attacker a
fbr-client sends files through sockets via socket.io and webRTC. fbr-client is vulnerable to a directory traversal issue
dgard8.lab6 is a static file server. dgard8.lab6 is vulnerable to a directory traversal issue, giving an attacker access
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the fi
wind-mvc is an mvc framework. wind-mvc is vulnerable to a directory traversal issue, giving an attacker access to the fi
yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst
nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to
general-file-server node module suffers from a Path Traversal vulnerability due to lack of validation of currpath, which
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a maliciou
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a m
public node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a mal
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths wit
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certif
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / Proton
Huawei HG255s-10 V100R001C163B025SP02 has a path traversal vulnerability due to insufficient validation of the received
Path Traversal in Gateway in Mirasys DVMS Workstation 5.12.6 and earlier allows an attacker to traverse the file system
Redatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/tex
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the we
RSA Certificate Manager Versions 6.9 build 560 through 6.9 build 564 contain a path traversal vulnerability in the RSA C
Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.
A Local File Inclusion (LFI) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the
Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V
Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to r
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started