CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hote
Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to co
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni
Unauthenticated Arbitrary File Deletion in Contact Form Extender for Divi – Save Entries, File Upload & Countr
Unauthenticated Arbitrary File Deletion in Car Zone <= 3.7 versions.
Unauthenticated Arbitrary File Deletion in BookPro <= 1.1.0 versions.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in EMV JobCareer allows Pat
RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject pe
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Applicat
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adrian Tobey Groundhogg
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Swings Membership For
Adobe Experience Manager is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'
Animate is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability t
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a
Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne
The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachabl
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthent
OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature i
JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, the upload_wasm MCP tool accepted a
Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the valu
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creat
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary object
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 1
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7
PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system file
In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. P
TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attacke
Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute ar
iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code
An arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to ove
An arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overw
An arbitrary file overwrite vulnerability in InTouch Contacts & Caller ID APP v6.38.1 allows attackers to overwrite crit
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Versions prior to
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to befo
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the r
An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server)
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started