CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitiv
Frauscher Sensortechnik GmbH FDS001 for FAdC/FAdCi v1.3.3 and all previous versions are vulnerable to a path traversal v
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime
A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-cra
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtende
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Tra
Copyparty is a portable file server. Versions prior to 1.8.2 are subject to a path traversal vulnerability detected in t
rswag before 2.10.1 allows remote attackers to read arbitrary JSON and YAML files via directory traversal, because rswag
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTP
Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed au
Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the componen
In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Adv
The Jupiter X Core plugin for WordPress is vulnerable to arbitrary file downloads in versions up to, and including, 4.6.
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip
RTX TRAP v1.0 allows attackers to perform a directory traversal via a crafted request sent to the endpoint /data/.
Directory traversal vulnerability in Jinfornet Jreport 15.6 allows unauthenticated attackers to gain sensitive informati
Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
A path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to read arbitrary files v
A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbit
Nuclei is a vulnerability scanner. Prior to version 2.9.9, a security issue in the Nuclei project affected users utilizi
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perf
An issue in the SpreadSheetPlugin component of Foswiki v2.1.7 and below allows attackers to execute a directory traversa
1Panel is an open source Linux server operation and maintenance management panel. In version 1.4.3, arbitrary file reads
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sens
An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zol
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to imprope
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assista
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assista
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection
The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnera
Relative Path Traversal in GitHub repository cecilapp/cecil prior to 7.47.1.
Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal
mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not v
Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerabili
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passe
Relative path traversal vulnerability in Setelsa Security's ConacWin CB, in its 3.8.2.2 version and earlier, the exploit
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11), CP-8050 MASTER MODULE (All
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started