CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The Document Foundation
auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import
Discourse is an open source platform for community discussion. In affected versions an attacker can trick a target user
Nuxt is an open-source web development framework for Vue.js. Prior to 3.19.0 and 4.1.0, A client-side path traversal vul
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that
A directory traversal issue was discovered in OpenSlides before 4.2.5. Files can be uploaded to OpenSlides meetings and
OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment w
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list function
A vulnerability classified as problematic was found in China Mobile P22g-CIac 1.0.00.488. This vulnerability affects unk
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Fo
A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function down
The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate pa
A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownl
Directory traversal vulnerability in SOLIDserver IPAM v8.2.3. This vulnerability allows an authenticated user with admin
A path transversal vulnerability in Brocade Fabric OS 9.1.0 through 9.2.2 could allow a local admin user to gain acces
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process
Karmada is a Kubernetes management system that allows users to run cloud-native applications across multiple Kubernetes
org.gaul S3Proxy implements the S3 API and proxies requests. Users of the filesystem and filesystem-nio2 storage backend
Label Studio is an open source data labeling tool. A path traversal vulnerability in Label Studio SDK versions prior to
The ZOO-Project is an open source processing platform, released under MIT/X11 Licence. A vulnerability in ZOO-Project's
crun is an open source OCI Container Runtime fully written in C. In affected versions A malicious container image could
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for productio
Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, when copying
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routin
Path Traversal vulnerability in e-solutions e-management. This vulnerability could allow an attacker to access confident
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the expl
Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attack
Improper Limitation of a Pathname caused a Path Traversal vulnerability in Sparx Systems Pro Cloud Server. This vulnera
Atheos is a self-hosted browser-based cloud IDE. Prior to v602, similar to GHSA-rgjm-6p59-537v/CVE-2025-22152, the `$tar
PNETLab 4.2.10 does not properly sanitize user inputs in its file access mechanisms. This allows attackers to perform di
auth-js is an isomorphic Javascript library for Supabase Auth. Prior to version 2.70.0, the library functions getUserByI
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an ex
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modul
A path traversal vulnerability exists in multiple models of Selea Targa IP OCR-ANPR cameras, including iZero, Targa 512,
A path traversal vulnerability exists in the Karel IP1211 IP Phone's web management panel. The /cgi-bin/cgiServer.exx en
An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 0.4.3 lack input validation for
The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.
GitForge.jl is a unified interface for interacting with Git "forges." Versions prior to 5.9.1 lack input validation of i
A path traversal vulnerability exists in the Leadsec SSL VPN (formerly Lenovo NetGuard), allowing unauthenticated attack
A path traversal vulnerability exists in the web management interface of D-Link DSL-2730U, DSL-2750U, and DSL-2750E ADSL
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versio
An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects
A directory traversal vulnerability exists in ColoradoFTP Server ≤ 1.3 Build 8 for Windows, allowing unauthenticated att
A path traversal vulnerability exists in Linknat VOS Manager versions prior to 2.1.9.07, including VOS2009 and early VOS
An unauthenticated file download vulnerability exists in LimeSurvey versions from 2.0+ up to and including 2.06+ Build 1
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started