CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Syst
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Syst
This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Ente
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Syst
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of NetGain Syst
This vulnerability allows remote attackers to delete arbitrary files on vulnerable installations of NetGain Systems Ente
This vulnerability allows remote attackers to overwrite files on vulnerable installations of NetGain Systems Enterprise
This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems E
This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems E
This vulnerability allows remote attackers to overwrite arbitrary files on vulnerable installations of NetGain Systems E
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authen
IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker to traverse directories on the system.
The git repository tag rest resource in Atlassian Bitbucket Server from version 3.7.0 before 4.14.11 (the fixed version
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensiti
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 wa
A Remote Denial of Service vulnerability in HPE Intelligent Management Center (iMC) PLAT version iMC Plat 7.3 E0504P2 wa
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Ooz
Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base
On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access t
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbit
In Dell Storage Manager versions earlier than 16.3.20, the EMConfigMigration service is affected by a directory traversa
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
Digital Guardian Management Console 7.1.2.0015 has a Directory Traversal issue.
IBM Security QRadar SIEM 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker co
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, a
A path traversal vulnerability exists in Jenkins HTML Publisher Plugin 1.15 and older in HtmlPublisherTarget.java that a
A vulnerability in the web management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an a
A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify
An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.htm
The 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8
augustine node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malic
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write th
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and a
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilenam
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malici
glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerabi
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerabi
An issue was discovered in MetInfo 6.0.0. admin/app/batch/csvup.php allows remote attackers to delete arbitrary files vi
An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be perform
The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 a
The vulnerability exists within processing of sendmail.php in Schneider Electric U.motion Builder software versions prio
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable t
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot d
A directory traversal flaw in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows an authenticated attacker to writ
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started