Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 79/161
6.5
CVE-2024-5017

In WhatsUp Gold versions released before 2023.1.3, a path traversal vulnerability exists. A specially crafted unauthenti

6.5
CVE-2024-37547

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Livemesh Livemesh Addons

6.5
CVE-2024-37454

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AWSM Innovations AWSM Te

6.5
CVE-2024-37499

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vCita Online Booking & S

6.5
CVE-2024-38704

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DynamicWebLab WordPress

6.5
CVE-2024-38715

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExS ExS Widgets allows P

6.5
CVE-2024-38716

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Blue Plugins Events Cale

6.5
CVE-2024-31947

StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a c

6.5
CVE-2024-39036

SeaCMS v12.9 is vulnerable to Arbitrary File Read via admin_safe.php.

6.5
CVE-2024-40617

Path traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated atta

6.5
CVE-2024-3934

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to Path Traversal in versions 7.3.0 to 7.5.

6.5
CVE-2024-39688

Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is concatenated wi

6.5
CVE-2024-38772

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetWidgets fo

6.5
CVE-2024-7323

Digiwin EasyFlow .NET lacks proper access control for specific functionality, and the functionality do not adequately fi

6.5
CVE-2024-7564

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo

6.5
CVE-2024-21877

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in

6.5
CVE-2024-42474

Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a s

6.5
CVE-2024-43129

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs a

6.5
CVE-2024-43138

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Ma

6.5
CVE-2024-43165

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allow

6.5
CVE-2024-7602

Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remo

6.5
CVE-2024-45188

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal

6.5
CVE-2024-45189

Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal

6.5
CVE-2024-6789

A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 2

6.5
CVE-2024-6312

The Funnelforms Free plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including,

6.5
CVE-2024-7744

In WS_FTP Server versions before 8.8.8 (2022.0.8), an Improper Limitation of a Pathname to a Restricted Directory ('Path

6.5
CVE-2024-43957

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Sk. Abul Hasan Animated

6.5
CVE-2024-45074

IBM webMethods Integration 10.15 could allow an authenticated user to traverse directories on the system. An attacker co

6.5
CVE-2024-8585

Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowi

6.5
CVE-2024-8778

OMFLOW from The SYSCOM Group does not properly validate user input of the download functionality, allowing remote attack

6.5
CVE-2024-45816

Backstage is an open framework for building developer portals. When using the AWS S3 or GCS storage provider for TechDoc

6.5
CVE-2024-46644

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.

6.5
CVE-2024-46646

eNMS up to 4.7.1 is vulnerable to Directory Traversal via /download/file.

6.5
CVE-2024-46647

eNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.

6.5
CVE-2024-6786

The vulnerability allows an attacker to craft MQTT messages that include relative path traversal sequences, enabling the

6.5
CVE-2024-43996

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ElementsKit ElementsKit

6.5
CVE-2024-9224

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1

6.5
CVE-2024-46977

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.

6.5
CVE-2024-9100

Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnera

6.5
CVE-2024-47818

Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete

6.5
CVE-2024-47164

Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of di

6.5
CVE-2024-7514

The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient

6.5
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage lib

6.5
CVE-2024-20379

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerl

6.5
CVE-2024-51751

Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadB

6.5
CVE-2024-11215

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web ser

6.5
CVE-2024-11238

A vulnerability, which was classified as critical, was found in Landray EKP up to 16.0. This affects the function delPre

6.5
CVE-2024-48071

E-cology has a directory traversal vulnerability. An attacker can exploit this vulnerability to delete the server direct

6.5
CVE-2024-52056

Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any

6.5
CVE-2023-51648

Allegra getFileContentAsString Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remot

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started