CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A path traversal vulnerability exists in RIPS Scanner version 0.54. The vulnerability allows remote attackers to read ar
A path traversal vulnerability exists in httpdasm version 0.92, a lightweight Windows HTTP server, that allows unauthent
An unauthenticated path traversal vulnerability exists in Dicoogle PACS Web Server version 2.5.0 and possibly earlier. T
Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3,
A path traversal vulnerability exists in A10 Networks AX Loadbalancer versions 2.6.1-GR1-P5, 2.7.0, and earlier. The vul
A local privilege escalation vulnerability exists in Agnitum Outpost Internet Security 8.1 that allows an unprivileged u
A directory traversal vulnerability exists in Linksys router's web interface (tested on the E1500 model firmware version
A path traversal vulnerability exists in the Netgear SPH200D Skype phone firmware versions <= 1.0.4.80 in its embedded w
XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Auth
: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploade
Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is
Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to im
S40 CMS v0.4.2 contains a path traversal vulnerability in its index.php page handler. The p parameter is not properly sa
QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of us
UnForm Server Manager versions prior to 10.1.12 expose an unauthenticated file read vulnerability via its log file analy
Copier library and CLI app for rendering project templates. Prior to 9.9.1, a safe template can currently read and write
Copier library and CLI app for rendering project templates. From 7.1.0 to before 9.9.1, Copier suggests that it's safe t
Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote atta
vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible
Barracuda products, confirmed in Spam & Virus Firewall, SSL VPN, and Web Application Firewall versions prior to October
dpanel is an open source server management panel written in Go. In versions 1.2.0 through 1.7.2, dpanel allows authentic
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Da
LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arb
SPON IP Network Broadcast System, a digital audio transmission platform developed by SPON Communications, contains an ar
QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the
A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account,
internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory
ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is ab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x7
A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.
Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of s
A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with r
astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink
Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cygwin target (`x86_64-pc-cygwin`) didn't correctly handle
Traccar is an open source GPS tracking system. Default installs of Traccar on Windows between versions 6.1- 6.8.1 and n
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/globa
Huijietong Cloud Video Platform contains a path traversal vulnerability that allows an unauthenticated attacker can supp
Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5
Docker Compose trusts the path information embedded in remote OCI compose artifacts. When a layer includes the annotatio
The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path
archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to fe
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on
CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1
PacsOne Server version 6.6.2 (prior versions are likely affected) contains a directory traversal vulnerability within th
A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could c
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory tr
Longjing Technology BEMS API versions up to and including 1.21 contains an unauthenticated arbitrary file download vulne
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started