CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability was found in composiohq composio up to 0.5.8 and classified as problematic. Affected by this issue is th
Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, a
A path handling issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3. An app may be a
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and
Dell Unity, versions prior to 5.4, contain a path traversal vulnerability in its svc_supportassist utility. An authenti
Dell Repository Manager, versions 3.4.2 through 3.4.4,contains a Path Traversal vulnerability in logger module. A local
Path traversal vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product installs a crafted UTAU
A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by thi
A remote code execution vulnerability in the project management of Wanxing Technology's Yitu project which allows an att
A vulnerability, which was classified as problematic, was found in KDE Plasma Workspace up to 5.93.0. This affects the f
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
Wasmer is a web assembly (wasm) Runtime supporting WASIX, WASI and Emscripten. If the preopened directory has a symlink
In JetBrains IntelliJ IDEA before 2023.3.3 path traversal was possible when unpacking archives
A path traversal vulnerability was reported in the Motorola Ready For application that could allow a local attacker to
The Directorist WordPress plugin before 7.5.4 is vulnerable to Local File Inclusion as it does not validate the file par
Zoho ManageEngine ADAudit Plus before 7270 allows admin users to view names of arbitrary directories via path traversal.
Owncast is an open source, self-hosted, decentralized, single user live video streaming and chat server. The Owncast app
The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.13
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown func
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie
Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local fi
IBM InfoSphere Information Server 11.7 could allow an authenticated privileged user to obtain the absolute path of the w
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet For
The Campbell Scientific CSI Web Server supports a command that will return the most recent file that matches a given exp
In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execut
Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Incl
`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers a
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is
The cap-std project is organized around the eponymous `cap-std` crate, and develops libraries to make it easy to write c
jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cau
matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerabl
The pathname of the root directory to a Restricted Directory ('Path Traversal') vulnerability in Korenix JetPort 5601 al
The game extension engine of versions 1.2.7.0 and earlier exposes some components, and attackers can construct parameter
The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that c
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can
path-sanitizer is a simple lightweight npm package for sanitizing paths to prevent Path Traversal. Prior to 3.1.0, the f
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the obje
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker wi
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versi
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker
Aqua Drive, in its 2.4 version, is vulnerable to a relative path traversal vulnerability. By exploiting this vulnerabili
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in ver
nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplyi
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject fi
Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensiti
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started