CWE-22
MITRE ↗Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Directory Traversal vulnerability in EverShop NPM versions before v.1.0.0-rc.8 allows a remote attacker to obtain sensit
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that coul
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) remo
Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows atta
A vulnerability has been found in sviehb jefferson up to 0.3 and classified as critical. This vulnerability affects unkn
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the a
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCR
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Software Foundation Apache MINA. In
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Schweitzer Engineering L
Argo CD is a declarative continuous deployment framework for Kubernetes. In Argo CD versions prior to 2.3 (starting at l
A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
An authenticated path traversal vulnerability exists in the ArubaOS command line interface. Successful exploitation of t
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when buildi
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Go Maps (formerly WP
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limit
The All-In-One Security (AIOS) WordPress plugin before 5.1.5 does not limit what log files to display in it's settings p
ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface.
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface.
Multiple authenticated path traversal vulnerabilities exist in the Aruba EdgeConnect Enterprise command line interface.
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an au
Ombi is an open source application which allows users to request specific media from popular self-hosted streaming serve
Improper Limitation of a Pathname leads to a Path Traversal vulnerability in the module King-Avis for Prestashop, allowi
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versio
Ghost is an open source content management system. Versions prior to 5.59.1 are subject to a vulnerability which allows
Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine wh
baserCMS is a website development framework. Prior to version 4.8.0, there is a Directory Traversal Vulnerability in the
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read ar
Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrati
Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1,
In TYPO3 11.5.24, the filelist component allows attackers (who have access to the administrator panel) to read arbitrary
Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vert
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classif
A vulnerability classified as problematic has been found in fastcms. This affects an unknown part of the file admin/Temp
A path traversal vulnerability was identified in the HL7 sensor in PRTG 23.2.84.1566 and earlier versions where an authe
A path traversal vulnerability was identified in the WMI Custom sensor in PRTG 23.2.84.1566 and earlier versions where a
A path traversal vulnerability was identified in the SQL v2 sensors in PRTG 23.2.84.1566 and earlier versions where an a
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this iss
Pimcore is an open source data and experience management platform. Prior to version 10.5.21, the `/admin/misc/script-pro
A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitr
A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function
A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterio
A vulnerability has been found in AlliedModders AMX Mod X on Windows and classified as critical. This vulnerability affe
A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown functi
A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing
Rapid7 Velociraptor did not properly sanitize the client ID parameter to the CreateCollection API, allowing a directory
An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal.
Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form v
Frequently Asked Questions
What is CWE-22?
CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-22?
There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.
How can I protect against CWE-22 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.
Detect CWE-22 Vulnerabilities
CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.
Get Started