CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V15 (All versions), Totally Int
Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated
Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a
Path traversal in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows may allow an a
MyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with hig
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the cu
The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file upl
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of the
Authenticated path traversal vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of the
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 th
The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via
Path Traversal in GitHub repository froxlor/froxlor prior to 2.0.20.
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerabilit
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) a
Directory Traversal vulnerability in Textpattern CMS v4.8.8 allows a remote authenticated attacker to execute arbitrary
A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Busine
A vulnerability in the EdgeConnect SD-WAN Orchestrator web-based management interface allows remote authenticated users
Aria Operations for Networks contains an arbitrary file write vulnerability. An authenticated malicious actor with admin
Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP server
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can crea
Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Dir
Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated C
IThe Quttera Web Malware Scanner WordPress plugin before 3.4.2.1 does not validate user input used in a path, which coul
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability
NVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path travers
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A
metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to creat
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 are affected by a path traversal vulnerability, which
ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrar
PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitr
An issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauth
A vulnerability in the CryptoService function of Cisco Duo Device Health Application for Windows could allow an authenti
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/upload`
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API manageoverlayimage.cgi was vulnera
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup.cgi was vulnerable to pat
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perf
Mattermost version 2.10.0 and earlier fails to sanitize deeplink paths, which allows an attacker to perform CSRF attacks
The Netskope client service running with NT\SYSTEM privileges accepts network connections from localhost to start variou
Azure Arc-Enabled Servers Elevation of Privilege Vulnerability
Gradle is a build tool with a focus on build automation and support for multi-language development. When Gradle writes a
Gradle is a build tool with a focus on build automation and support for multi-language development. In affected versions
A potential security vulnerability has been identified in HPE OfficeConnect 1820, and 1850 switch series. The vulnerabil
FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to a path traversal, which could allow an attacke
PrestaShop is an open source e-commerce web application. Prior to version 8.1.1, the `displayAjaxEmailHTML` method can b
Dover Fueling Solutions MAGLINK LX Web Console Configuration versions 2.5.1, 2.5.2, 2.5.3, 2.6.1, 2.11, 3.0, 3.2, and 3.
An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mount
IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker cou
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM pri
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when build
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started