CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to
An issue in Zip Swift v2.1.2 allows attackers to execute a path traversal attack via a crafted zip entry.
An issue in ZIPFoundation v0.9.16 allows attackers to execute a path traversal via extracting a crafted zip file.
An issue in Archive v3.3.7 allows attackers to execute a path traversal via extracting a crafted zip file.
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a
In computeValuesFromData of FileUtils.java, there is a possible way to insert files to other apps' external private dire
Relative path traversal vulnerability in Shihonkanri Plus Ver9.0.3 and earlier allows a local attacker to execute an arb
Directory Traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 version Alpha 1.3.9, allows local attackers to ex
A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All
The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains a vulnerability that allows an attacker with lo
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au
A path traversal vulnerability has been reported to affect Music Station. If exploited, the vulnerability could allow au
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1,
In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using t
aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this
OpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a p
Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T
Path Traversal vulnerability in Deytek Informatics FileOrbis File Management System allows Path Traversal. This issue a
An issue was discovered in FC46-WebBridge on GE Grid Solutions MS3000 devices before 3.7.6.25p0_3.2.2.17p0_4.7p0. A vuln
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated atta
kraken <= 0.1.4 has an arbitrary file read vulnerability via the component testfs.
A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directo
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tenso
IBM Business Automation Workflow 22.0.2 could allow a remote attacker to traverse directories on the system. An attacke
A path traversal vulnerability exists in Sage FRP 1000 before November 2019. This allows remote unauthenticated attacker
Italtel NetMatch-S CI 5.2.0-20211008 allows Absolute Path Traversal under NMSCI-WebGui/SaveFileUploader. An unauthentica
Versions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the fi
A directory traversal vulnerability exists in the httpd update.cgi functionality of FreshTomato 2022.5. A specially craf
ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unau
Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal.
In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker
Cellinx NVT v1.0.6.002b was discovered to contain a local file disclosure vulnerability via the component /cgi-bin/GetFi
Sme.UP TOKYO V6R1M220406 was discovered to contain an arbitrary file download vulnerabilty via the component /ResourceSe
Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the fil
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
An unauthenticated path traversal vulnerability affects the "STAGIL Navigation for Jira - Menu & Themes" plugin before 2
A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transf
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directo
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allo
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a
Hasura is an open-source product that provides users GraphQL or REST APIs. A path traversal vulnerability has been disco
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary f
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManage
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started