Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 40/161
CVE-2026-45419

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call Template

CVE-2026-45533

DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can a

CVE-2026-59863

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/worksp

CVE-2026-59864

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin g

CVE-2026-59866

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientCl

CVE-2026-53535

Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-conf

CVE-2026-55629

Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cg

CVE-2026-44177

Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correct

CVE-2026-15343

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code executio

CVE-2026-60027

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla

CVE-2026-47394

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, the fix for GHSA-9mqq-jqxf-grvw / CVE-2026-44336 is in

CVE-2026-47397

PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents t

CVE-2026-47425

Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `Entry

CVE-2026-56844

A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate

CVE-2026-47669

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api

CVE-2026-65765

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths

CVE-2026-65878

Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path valida

CVE-2026-66397

phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, al

CVE-2026-54659

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18

CVE-2026-44943

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows rem

CVE-2026-53502

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path

CVE-2026-67309

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider

CVE-2026-58072

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead

CVE-2026-47764

pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnera

CVE-2026-47682

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0

CVE-2026-71309

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.

CVE-2026-64653

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable pat

CVE-2026-64677

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not

CVE-2026-71476

Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx sel

CVE-2026-66491

Joomla Extension - phoca.cz - Arbitrary File Read in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths in the g

CVE-2026-66492

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths

CVE-2026-66493

Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.3 - Improper limitation of paths

CVE-2026-66914

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated

CVE-2026-62992

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio

CVE-2026-62996

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From

CVE-2026-47659

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47661

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior

CVE-2026-47243

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th

CVE-2026-66484

GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar arch

CVE-2026-12339

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive contai

CVE-2026-72770

n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operati

CVE-2026-72773

n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc

CVE-2026-32677

Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an esca

CVE-2026-67285

Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An u

CVE-2026-67286

Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8

CVE-2026-73407

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/

CVE-2026-45774

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compli

CVE-2026-72814

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-exi

CVE-2026-19880

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulne

CVE-2026-57471

Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started