CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp
In Octopus Deploy 3.x before 3.15.4, an authenticated user with PackagePush permission to upload packages could upload a
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory trave
Directory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a
Directory traversal vulnerability in AttacheCase 2.8.2.8 and earlier and 3.2.0.4 and earlier allows remote attackers to
Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and Atta
Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks conta
TIT-AL00C583B211 has a directory traversal vulnerability which allows an attacker to obtain the files in email applicati
Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remot
An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to cons
An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read a
In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary
A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attack
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
Directory traversal vulnerability in MetInfo 5.3.17 allows remote attackers to read information from any ini format file
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote at
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could sen
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the i
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a cra
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitra
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators t
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read
Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path trav
EMC Data Protection Advisor prior to 6.4 contains a path traversal vulnerability. A remote authenticated high privileged
In Sitecore 8.2, there is absolute path traversal via the shell/Applications/Layouts/IDE.aspx fi parameter and the admin
Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary file
Directory traversal vulnerability in the doSendObjectInfo method in frameworks/av/media/mtp/MtpServer.cpp in Android 4.4
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a direct
Directory traversal vulnerability in Contao before 3.2.19, and 3.4.x before 3.4.4 allows remote authenticated "back end"
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon
Directory traversal vulnerability in OneThird CMS Show Off v1.85 and earlier. Show Off v1.85 en and earlier allows an at
A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the s
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started