CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a special
Softnext Mail SQR Expert is an email management platform, it has a Local File Inclusion (LFI) vulnerability in a mail de
IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker co
An issue was discovered in NOKIA NFM-T R19.9. Relative Path Traversal can occur under /oms1350/data/cpb/log of the Netwo
An issue was discovered in NOKIA NFM-T R19.9. An Absolute Path Traversal vulnerability exists under /cgi-bin/R19.9/viewl
The WP Mail Log WordPress plugin before 1.1.3 does not properly validate file path parameters when attaching files to em
A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown
A vulnerability, which was classified as critical, was found in IP Blacklist Cloud Plugin up to 3.42 on WordPress. This
An issue has been discovered in GitLab affecting all versions starting from 8.10 before 16.0.8, all versions starting fr
Pimcore is an Open Source Data & Experience Management Platform: PIM, MDM, CDP, DAM, DXP/CMS & Digital Commerce. A path
Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files an
A vulnerability, which was classified as critical, has been found in Yongyou UFIDA-NC up to 20230807. This issue affects
Terraform version 1.0.8 through 1.5.6 allows arbitrary file write during the `init` operation if run on maliciously craf
Dell SmartFabric Storage Software v1.4 (and earlier) contains a Path Traversal Vulnerability in the HTTP interface. A r
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball s
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a mal
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affe
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7
Before importing a project into Vuforia, a user could modify the “resourceDirectory” attribute in the appConfig.jso
Zoom for Android clients before version 5.13.0 contain a path traversal vulnerability. A third party app could exploit t
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/
Arduino Create Agent is a package to help manage Arduino development. This vulnerability affects the endpoint `/v2/pkgs/
NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can upload and download arbitrary file
Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` fun
A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to d
A vulnerability has been identified in SIMATIC Cloud Connect 7 CC712 (All versions >= V2.0 < V2.1), SIMATIC Cloud Connec
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path t
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path t
AMI BMC contains a vulnerability in the IPMI handler, where an attacker can upload and download arbitrary files under ce
AWS SDK for PHP is the Amazon Web Services software development kit for PHP. Within the scope of requests to S3 object k
There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that t
Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby uns
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacke
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacke
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files o
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x be
Path traversal vulnerability in Samsung Cloud prior to version 5.3.0.32 allows attacker to access specific png file.
A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, Forti
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when access
The Wrangler command line tool (<[email protected] or <[email protected]) was affected by a directory traversal vulnerabil
Path traversal vulnerability in ACERA 1320 firmware ver.01.26 and earlier, and ACERA 1310 firmware ver.01.26 and earlier
Metersphere is an opensource testing framework. Files uploaded to Metersphere may define a `belongType` value with a rel
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine lear
A vulnerability was found in soerennb eXtplorer up to 2.1.12 and classified as critical. Affected by this issue is some
A vulnerability was found in soerennb eXtplorer up to 2.1.12. It has been classified as critical. This affects an unknow
A vulnerability classified as critical has been found in JATOS. Affected is the function ZipUtil of the file modules/com
A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the
A vulnerability classified as critical was found in hoffie larasync. This vulnerability affects unknown code of the file
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started