CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
A vulnerability was found in stakira OpenUtau. It has been classified as critical. This affects the function VoicebankIn
A vulnerability has been found in SUKOHI Surpass and classified as critical. This vulnerability affects unknown code of
A vulnerability classified as critical has been found in YunoHost-Apps transmission_ynh. Affected is an unknown function
A vulnerability was found in saxman maps-js-icoads and classified as critical. This issue affects some unknown processin
A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects t
A vulnerability, which was classified as critical, was found in abreen Apollo. This affects an unknown part. The manipul
A vulnerability has been found in frontaccounting faplanet and classified as critical. This vulnerability affects unknow
A vulnerability has been found in youngerheart nodeserver and classified as critical. Affected by this vulnerability is
ubireader_extract_files is vulnerable to path traversal when run against specifically crafted UBIFS files, allowing the
A path traversal vulnerability affects jefferson's JFFS2 filesystem extractor. By crafting malicious JFFS2 files, attack
A path traversal vulnerability affects yaffshiv YAFFS filesystem extractor. By crafting a malicious YAFFS file, an attac
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are n
hawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high
OpenRefine is a free, open source tool for data processing. A carefully crafted malicious OpenRefine project tar file ca
A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to
In update of MmsProvider.java, there is a possible way to change directory permissions due to a path traversal error. Th
hyper-bump-it is a command line tool for updating the version in project files.`hyper-bump-it` reads a file glob pattern
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the admin panel, an attacker
An issue was discovered in Croc through 9.6.5. A sender can cause a receiver to overwrite files during ZIP extraction.
A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPr
Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $fil
A vulnerability classified as critical was found in SourceCodester Online Computer and Laptop Store 1.0. Affected by thi
WordPress Core is vulnerable to Directory Traversal in versions up to, and including, 6.2, via the ‘wp_lang’ parameter.
Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG26
Headwind MDM Web panel 5.22.1 is vulnerable to Directory Traversal. The application uses an API call to move the uploade
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensit
A path traversal vulnerability [CWE-23] in the API of FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versio
The Borg theme before 1.1.19 for Backdrop CMS does not sufficiently sanitize path arguments that are passed in via a URL
A vulnerability classified as critical was found in hgzojer Vocable Trainer up to 1.3.0 on Android. This vulnerability a
The Always On Display (AOD) has a path traversal vulnerability in theme files. Successful exploitation of this vulnerabi
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion
spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.
NetApp Blue XP Connector versions prior to 3.9.25 expose information via a directory listing. A new Connector architectu
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during f
Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server
Advent/SSC Inc. Tamale RMS < 23.1 is vulnerable to Directory Traversal. If one traverses to the affected URL, one enumer
An issue in /functions/fbaorder.php of Prestashop amazon before v5.2.24 allows attackers to execute a directory traversa
Precisely Spectrum Spatial Analyst 20.01 is vulnerable to Directory Traversal.
`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. Th
AudimexEE 15.0 was discovered to contain a full path disclosure vulnerability.
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traver
GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provide
IBM License Metric Tool 9.2 could allow a remote attacker to traverse directories on the system. An attacker could send
Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/d
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul
TorchServe is a tool for serving and scaling PyTorch models in production. Starting in version 0.1.0 and prior to versio
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions i
Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started