CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrar
PHP-IMAP is a wrapper for common IMAP communication without the need to have the php-imap module installed / enabled. Pr
JumpServer is an open source bastion host. Logged-in users can access and modify the contents of any file on the system.
ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where
An arbitrary file upload vulnerability in the /api/upload component of zdir v3.2.0 allows attackers to execute arbitrary
A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A
IdentityIQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentityIQ 8.2 and all 8.2 patch levels prior to 8.2p5, Identity
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 an
A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated
Zoho ManageEngine Desktop Central and Desktop Central MSP before 10.1.2137.2 allow directory traversal via computerName
Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsu
go-used-util has commonly used utility functions for Go. Versions prior to 0.0.34 have a ZipSlip issue when using fsutil
The CODESYS runtime system in multiple versions allows an remote low privileged attacker to use a path traversal vulnera
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly re
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, wri
Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory
SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker wit
A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to ex
Xibo is a content management system (CMS). A path traversal vulnerability exists in the Xibo CMS whereby a specially cra
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in SonicWall GMS and Analyt
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This f
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server throu
Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create ar
An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and
Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.
Atos Unify OpenScape Common Management Portal V10 before V10 R4.17.0 and V10 R5.1.0 allows an authenticated attacker to
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerabil
An arbitrary file upload and directory traversal vulnerability exist in the file upload functionality of the System Setu
Arbitrary file upload to web root in the IDAttend’s IDWeb application 3.1.013 allows authenticated attackers to upload d
An issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker c
Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbi
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any fi
Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this
Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2.
SAP NetWeaver AS for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757,
In SAP NetWeaver (BI CONT ADDON) - versions 707, 737, 747, 757, an attacker can exploit a directory traversal flaw in a
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can
IBM Security Directory Server 7.2.0 could allow a remote attacker to traverse directories on the system. An attacker cou
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to Directory Traversal in versions up to, an
Gravitee API Management before 3.15.13 allows path traversal through HTML injection.
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based
ShokoServer is a media server which specializes in organizing anime. In affected versions the `/api/Image/WithPath` endp
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker wi
MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archiv
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory st
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte
Printer service fails to adequately handle user input, allowing an remote unauthorized users to navigate beyond the inte
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started