CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
In JetBrains TeamCity before 2023.11.3 path traversal allowed reading data within JAR archives
Digdag is an open source tool that to build, run, schedule, and monitor complex pipelines of tasks across various platfo
Possible path traversal in Apache OFBiz allowing file inclusion. Users are recommended to upgrade to version 18.12.12, t
IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse director
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete f
The HCL BigFix Inventory server is vulnerable to path traversal which enables an attacker to read internal application f
DocsGPT is a GPT-powered chat for documentation. DocsGPT is vulnerable to unauthenticated limited file write in routes.p
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using
LG SuperSign Media Editor getSubFolderList Directory Traversal Information Disclosure Vulnerability. This vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by S
In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system pa
@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if
The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive
A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enum
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileD
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Path Traversal vulnerability exists Wug.UI.Areas.W
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Arbitrary File Read issue exists in Wug.UI.Areas
A vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the
An issue was discovered in Artifex Ghostscript before 10.03.1. Path traversal and command execution can occur (via a cra
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Milan Petrovic GD Rating
A vulnerability was found in SourceCodester Insurance Management System 1.0. It has been declared as problematic. Affect
The InfoScan client download page can be intercepted with a proxy, to expose filenames located on the system, which cou
openHAB, a provider of open-source home automation software, has add-ons including the visualization add-on CometVisu. C
When mounting a remote filesystem using NFS, the kernel did not sanitize remotely provided filenames for the path separa
A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloa
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Element
A vulnerability was found in ZZCMS 2023. It has been declared as critical. This vulnerability affects unknown code of th
Overleaf is a web-based collaborative LaTeX editor. Overleaf Community Edition and Server Pro prior to version 5.0.7 (or
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read p
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.
Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does no
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch f
A Directory listing issue was found in PHPGurukul User Registration & Login and User Management System 3.2, which allows
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in FitNesse releases prior t
Statmatic is a Laravel and Git powered content management system (CMS). Prior to version 5.17.0, assets uploaded with ap
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Path
SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software b
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and befor
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to
iTop is an IT service management platform. Dashboard editor : can load multiple files and URL, and full path disclosure
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic WordPress all
Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious
Vulnerability in Delinea Centrify PAS v. 21.3 and possibly others. The application is prone to the path traversal vulner
In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid
Autolab is a course management service that enables instructors to offer autograded programming assignments to their stu
Webtrees 2.1.18 is vulnerable to Directory Traversal. By manipulating the "media_folder" parameter in the URL, an attack
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started