CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova WorkstationST
The UserPro - Community and User Profile WordPress Plugin plugin for WordPress is vulnerable to Directory Traversal in a
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in pitinca XLSXviewer xlsx-
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgra
GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ dir
In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../
SAPCAR improperly sanitizes the file paths while extracting SAPCAR archives. Due to this, an attacker could craft a mali
A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and h
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Komtera Technolgies KLog
Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00
File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated inpu
A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected i
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5
A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privi
An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a direct
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14
A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows enviro
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 thr
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute a
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
A vulnerability classified as critical has been found in themanojdesai python-a2a up to 0.5.5. Affected is the function
A vulnerability classified as critical was found in Upsonic up to 0.55.6. This vulnerability affects the function os.pat
A vulnerability, which was classified as critical, was found in TransformerOptimus SuperAGI up to 0.0.14. Affected is th
A vulnerability has been found in OpenBMB XAgent up to 1.0.0 and classified as critical. Affected by this vulnerability
A vulnerability was found in xlang-ai OpenAgents up to ff2e46440699af1324eb25655b622c4a131265bb and classified as critic
A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For
In testGrantSlicePermission of SliceManagerTest.java, there is a possible permanent denial of service due to a path trav
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in i
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m
A vulnerability was found in 1541492390c yougou-mall up to 0a771fa817c924efe52c8fe0a9a6658eee675f9f. This impacts the fu
A vulnerability classified as critical was found in CmsEasy 7.7.7.9. This vulnerability affects the function backAll_act
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to Exter
A vulnerability classified as critical has been found in CmsEasy 7.7.7.9. This affects the function deletedir_action/res
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affec
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3
A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this
A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unkno
A vulnerability classified as critical was found in zhijiantianya ruoyi-vue-pro 2.4.1. This vulnerability affects unknow
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started