CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
DBLTek GoIP-1 firmware versions up to and including GHSFVT-1.1-67-5 contain a local file inclusion vulnerability. The de
Ozeki SMS Gateway versions up to and including 10.3.208 contain a path traversal vulnerability. Successful exploitation
BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize in
A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effe
A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl
UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do
Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects
APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access se
NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFIL
Streama versions 1.10.0 through 1.10.5 and prior to commit b7c8767 contain a combination of path traversal and server-si
KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Re
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulner
DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not pre
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand an
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows Fil
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products:
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and
The File Manager and File Manager Pro plugins for WordPress are vulnerable to Directory Traversal in versions up to, and
Wings is the server control plane for Pterodactyl Panel. This vulnerability impacts anyone running the affected versions
There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authe
A path traversal issue potentially leading to remote code execution in Genie for all versions prior to 4.3.18
Vulnerability discovered by executing a planned security audit. Improper Limitation of a Pathname to a Restricted Direc
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnera
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overw
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p
A path traversal vulnerability was discovered in go-git versions prior to v5.11. This vulnerability allows an attacker t
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local var
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into t
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
Sharp NEC Displays (P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local Fil
Directory Traversal vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path tra
The functionality for file download in HGiga OAKlouds' certain modules contains an Arbitrary File Read and Delete vulner
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An una
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
A path traversal vulnerability exists in the Java version of CData API Server < 23.4.8844 when running using the embedde
A path traversal vulnerability exists in the Java version of CData Connect < 23.4.8846 when running using the embedded J
The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of us
qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTIO
Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page para
Directory Traversal vulnerability in TaoCMS v.3.0.2 allows a remote attacker to execute arbitrary code and obtain sensit
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started