CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Allegra downloadAttachmentGlobal Directory Traversal Information Disclosure Vulnerability. This vulnerability allows rem
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS DELUCKS SEO delu
pghoard is a PostgreSQL backup daemon and restore tooling that stores backup data in cloud object stores. A vulnerabilit
Path Traversal: '.../...//' vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affect
In WhatsUp Gold versions released before 2024.0.2, an authenticated user can use a specially crafted HTTP request that c
There is an unsafe DLL loading vulnerability in ZTE ZXCLOUD iRAI. Due to the program failed to adequately validate the
Helm is a tool for managing Charts. Charts are packages of pre-configured Kubernetes resources. When either the Helm cli
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and
The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and
CMSeasy 7.7.7.9 is vulnerable to code execution.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QODE Interactive Qi Addo
: Relative Path Traversal vulnerability in B&R Industrial Automation Automation Studio allows Relative Path Traversal.Th
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized
A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability
stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui
A vulnerability was found in cym1102 nginxWebUI up to 3.9.9. It has been rated as critical. Affected by this issue is th
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force Ultimat
A vulnerability classified as critical has been found in anji-plus AJ-Report up to 1.4.1. This affects the function deco
The file upload feature in OTRS and ((OTRS)) Community Edition has a path traversal vulnerability. This issue permits au
An issue was discovered in Artifex Ghostscript before 10.03.1. There is path traversal (via a crafted PostScript documen
ICEcoder 8.1 contains a Path Traversal vulnerability via lib/backup-versions-preview-loader.php.
A path traversal vulnerability exists in the Xiaomi File Manager application product(international version). The vulnera
audiobookshelf is a self-hosted audiobook and podcast server. A non-admin user is not allowed to create libraries (or ac
A vulnerability was found in JFinalCMS up to 1.0. It has been rated as critical. This issue affects the function delete
A vulnerability, which was classified as critical, was found in SourceCodester Simple Forum-Discussion System 1.0. Affec
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to constru
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe
E.D.D.I (Enhanced Dialog Driven Interface) is a middleware to connect and manage LLM API bots. A path traversal vulnerab
mailcow: dockerized is an open source groupware/email suite based on docker. A security vulnerability has been identifie
Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device comp
The vulnerability allows an attacker to access sensitive files on the server by confusing the agent with incorrect file
Path traversal vulnerability in the Bluetooth module Impact: Successful exploitation of this vulnerability may affect se
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file
Directory traversal vulnerability in the cust module Impact: Successful exploitation of this vulnerability will affect a
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Valiano Unite Gallery Li
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and c
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul
PrestaShop is an open-source e-commerce platform. Starting in version 8.1.0 and prior to version 8.1.4, PrestaShop is vu
MesonLSP is an unofficial, unendorsed language server for meson written in C++. A vulnerability in versions prior to 4.1
SPX (aka php-spx) through 0.4.15 allows SPX_UI_URI Directory Traversal to read arbitrary files.
CrateDB is a distributed SQL database that makes it simple to store and analyze massive amounts of data in real-time. Th
Dell OpenManage Enterprise, v4.0 and prior, contain(s) a path traversal vulnerability. An unauthenticated remote attacke
Path Traversal found in OpenText™ iManager 3.2.6.0200. This can lead to privilege escalation or file disclosure.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText NetIQ Access Ma
An issue in the Http_handle object of VONETS VAP11G-300 v3.3.23.6.9 allows attackers to access sensitive files via a dir
MarkUs, a web application for the submission and grading of student assignments, is vulnerable to path traversal in vers
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vul
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started