CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
A vulnerability, which was classified as problematic, was found in SourceCodester Online Student Clearance System 1.0. T
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. I
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authentic
A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerabilit
A vulnerability has been found in Dromara RuoYi-Vue-Plus 5.4.0 and classified as critical. Affected by this vulnerabilit
A vulnerability classified as critical has been found in SimStudioAI sim up to 0.1.17. Affected is the function handleLo
A security vulnerability has been detected in Kingdee Cloud-Starry-Sky Enterprise Edition up to 8.2. This issue affects
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an
Group-Office versions prior to 6.8.119 and prior to 25.0.20 provided by Intermesh BV contain a path traversal vulnerabil
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting w
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by thi
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform 1.0. Affected by this issue is som
Directory traversal vulnerability in Sync In server thru 1.1.1 allowing authenticated attackers to gain read and write a
A flaw has been found in Four-Faith Water Conservancy Informatization Platform 1.0. This affects an unknown function of
A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/res
A security flaw has been discovered in Campcodes Farm Management System 1.0. Affected by this issue is some unknown func
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by s
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4,
SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the A
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For
Due to an Information Disclosure vulnerability in SAP NetWeaver Application Server Java, internal metadata files could b
A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the fil
A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the f
Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for rout
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option i
A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java
A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is
A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown func
A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown cod
DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver
A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder vers
Directory Traversal vulnerability in Ianproxy v.0.1 and before allows a remote attacker to obtain sensitive information
Path traversal vulnerability in Samsung Members prior to version 5.0.00.11 allows attackers to read and write arbitrary
CrushFTP 9.x and 10.x through 10.8.4 and 11.x through 11.3.1 allows directory traversal via the /WebInterface/function/
Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows rem
A vulnerability, which was classified as critical, was found in givanz Vvvebjs up to 2.0.4. Affected is an unknown funct
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticat
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the corr
A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown pa
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You WPMasterToolK
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders Inc., WP Ult
An authenticated user who has read access to the juju controller model, may construct a remote request to download an ar
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in RealMag777 WOLF bulk-edi
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started