CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive
Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/`
Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information
An issue in Software FX Chart FX 7 version 7.0.4962.20829 allows attackers to enumerate and read files from the local fi
Path Traversal vulnerability in Linea Grafica "Multilingual and Multistore Sitemap Pro - SEO" (lgsitemaps) module for Pr
OpenRefine is a free, open source power tool for working with messy data and improving it. A jdbc attack vulnerability e
Directory Traversal vulnerability in Terrasoft, Creatio Terrasoft CRM v.7.18.4.1532 allows a remote attacker to obtain s
The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary loc
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data fiel
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a path traversal vulnerability in the httpuploadd service of the firmwa
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as .
Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.1
iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files
Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information vi
Directory traversal vulnerability exists in A.K.I Software's PMailServer/PMailServer2 products' CGIs included in Interna
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page param
An issue was discovered in OpenClinic GA 5.247.01. An attacker can perform a directory path traversal via the Page param
A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL witho
Allied Telesis AT-S115 1.2.0 devices before 1.00.024 with Boot Loader 1.00.006 allow Directory Traversal to achieve part
A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) c
INOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path
IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attac
Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerabilit
gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied inpu
A path traversal vulnerability exists in mlflow/mlflow version 2.9.2, allowing attackers to access arbitrary files on th
A path traversal vulnerability exists in the `_create_model_version()` function within `server/handlers.py` of the mlflo
A path traversal vulnerability exists in the mlflow/mlflow repository due to improper handling of URL parameters. By smu
A path traversal vulnerability exists in the mlflow/mlflow repository, specifically within the handling of the `artifact
Directory Traversal vulnerability in NEXSYS-ONE before v.Rev.15320 allows a remote attacker to obtain sensitive informat
ProQuality pqprintshippinglabels before v.4.15.0 is vulnerable to Directory Traversal via the pqprintshippinglabels modu
Directory Traversal vulnerability in FME Modules customfields v.2.2.7 and before allows a remote attacker to obtain sens
D-Link D-View TftpSendFileThread Directory Traversal Information Disclosure Vulnerability. This vulnerability allows rem
LG Simple Editor copyTemplateAll Directory Traversal Information Disclosure Vulnerability. This vulnerability allows rem
LG Simple Editor copyStickerContent Directory Traversal Information Disclosure Vulnerability. This vulnerability allows
LG SuperSign Media Editor ContentRestController getObject Directory Traversal Information Disclosure Vulnerability. This
AChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by usin
CmsEasy v7.7.7.9 was discovered to contain a local file inclusion vunerability via the file_get_contents function in the
Stakater Forecastle 1.0.139 and before allows %5C../ directory traversal in the website component.
imartinez/privategpt version 0.2.0 is vulnerable to a local file inclusion vulnerability that allows attackers to read a
A path traversal vulnerability exists in mlflow/mlflow version 2.11.0, identified as a bypass for the previously address
Path Traversal in Sonatype Nexus Repository 3 allows an unauthenticated attacker to read system files. Fixed in version
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spoonthemes Adifier Syst
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in BoldGrid Total Upkeep al
smanga 3.2.7 does not filter the file parameter at the PHP/get file flow.php interface, resulting in a path traversal vu
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter in th
A local file inclusion vulnerability exists in the JSON component of gradio-app/gradio version 4.25. The vulnerability a
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lol
A Local File Inclusion (LFI) vulnerability was identified in mlflow/mlflow, specifically in version 2.9.2, which was fix
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlie
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started