CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (1,995)
LocalSend versions before 1.17.0 have a path traversal vulnerability in file upload endpoints that allows attackers to write files to arbitrary locati...
Feb 25, 2025CVE-2025-22130 is a path traversal vulnerability in Soft Serve Git server that allows non-admin users to access and take over other users' repositorie...
Jan 8, 2025This vulnerability in python-libarchive allows attackers to perform directory traversal attacks when extracting ZIP archives, potentially writing file...
Dec 12, 2024This directory traversal vulnerability in Gogs allows attackers to read, write, or delete arbitrary files on the server by manipulating file paths in ...
Nov 15, 2024This vulnerability allows attackers to upload malicious files to MangoOS and Mango API systems, potentially leading to remote code execution. It affec...
Oct 25, 2024This vulnerability allows authenticated attackers to read arbitrary files on Pandora FMS servers through the plugin edition feature. It affects Pandor...
Oct 22, 2024A directory traversal vulnerability in Plasmoapp RPShare Fabric mod v1.0.0 allows remote attackers to read arbitrary files on the server by manipulati...
Sep 27, 2024This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks in the Eventin...
Sep 27, 2024The JetElements WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or hi...
Aug 16, 2024The JetTabs for Elementor WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level ac...
Aug 16, 2024This vulnerability allows attackers to write arbitrary files with system-level privileges on Samsung MagicINFO 9 Server by exploiting improper pathnam...
Aug 12, 2024This CVE describes a path traversal vulnerability that allows attackers to upload malicious files to arbitrary locations on the web server's filesyste...
Aug 7, 2024The WPBakery Visual Composer plugin for WordPress has a Local File Inclusion vulnerability that allows authenticated attackers with Author-level permi...
Aug 6, 2024This directory traversal vulnerability in Mgt-commerce CloudPanel allows authenticated attackers to read arbitrary files and execute code via the serv...
Jun 14, 2024A path traversal vulnerability in ONNX framework's download_model_with_test_data function allows attackers to overwrite arbitrary system files via mal...
Jun 6, 2024This CVE allows remote code execution in MLflow versions before 2.9.0 due to command injection vulnerability. Attackers can manipulate file paths when...
Jun 6, 2024This vulnerability allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges on NETGEAR ProSAFE Network Management System...
Jun 6, 2024The Cowidgets – Elementor Addons WordPress plugin contains a Local File Inclusion vulnerability in all versions up to 1.1.1. Authenticated attackers...
Jun 6, 2024This vulnerability in Ollama allows attackers to bypass path validation when retrieving model files, potentially leading to arbitrary file read or rem...
May 31, 2024CVE-2024-34060 is an arbitrary file write vulnerability in IrisEVTXModule that allows attackers to write malicious files to the server during EVTX fil...
May 23, 2024This vulnerability in Honeywell Saia PG5 Controls Suite allows remote attackers to execute arbitrary code by exploiting a directory traversal flaw in ...
May 3, 2024This vulnerability in Honeywell Saia PG5 Controls Suite allows remote attackers to execute arbitrary code by tricking users into opening malicious CAB...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by exploiting a directory traversa...
May 3, 2024This vulnerability in A10 Thunder ADC allows authenticated remote attackers to read and delete arbitrary files on the system through directory travers...
May 3, 2024This vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication and execute arbitrary code wit...
May 3, 2024Delta Electronics DIAEnergie software has a path traversal vulnerability that allows attackers to write files outside intended directories, potentiall...
May 3, 2024CVE-2024-32258 is a path traversal vulnerability in fceux 2.7.0's network server that allows unauthenticated attackers to overwrite arbitrary files on...
Apr 23, 2024This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to execute arbitrary commands with SYSTEM ...
Apr 19, 2024This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to execute arbitrary commands with SYSTEM ...
Apr 19, 2024This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It a...
Apr 19, 2024This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It a...
Apr 19, 2024This vulnerability in the HT Mega plugin for WordPress allows authenticated attackers with contributor-level access or higher to perform directory tra...
Apr 9, 2024Grav CMS versions before 1.7.45 contain a file upload path traversal vulnerability that allows attackers to upload malicious files to arbitrary locati...
Mar 21, 2024This is a high-severity path traversal vulnerability (CWE-22) in Confluence Data Center and Server that allows unauthenticated attackers to access or ...
Mar 19, 2024A directory traversal vulnerability in Devan-Kerman ARRP v0.8.1 and earlier allows remote attackers to execute arbitrary code via the dumpDirect funct...
Mar 19, 2024CVE-2024-27771 is a path traversal vulnerability in Unitronics Unistream Unilogic software that could allow remote code execution. Attackers can explo...
Mar 18, 2024The Elementor Addon Elements WordPress plugin has a directory traversal vulnerability in its render function. Authenticated attackers with contributor...
Mar 13, 2024This vulnerability allows attackers to bypass Node.js's experimental permission model by overwriting built-in path normalization functions, enabling p...
Feb 20, 2024CVE-2024-22514 is a path traversal vulnerability in iSpyConnect.com Agent DVR that allows attackers to execute arbitrary files by restoring a maliciou...
Feb 6, 2024This CVE describes a directory traversal vulnerability in Kihron ServerRPExposer v1.0.2 and earlier that allows remote attackers to execute arbitrary ...
Feb 2, 2024CVE-2024-21852 is a Zip Slip vulnerability in Rapid SCADA that allows attackers to upload malicious configuration files during unpacking, leading to a...
Feb 1, 2024This CVE describes an improper path traversal vulnerability in Dremio that allows authenticated users with limited folder access to bypass authorizati...
Jan 22, 2024The WooCommerce Currency Switcher FOX WordPress plugin before version 1.3.7 contains a Local File Inclusion (LFI) vulnerability via the 'woocs' shortc...
Jan 16, 2024CVE-2023-45722 is a path traversal vulnerability in HCL DRYiCE MyXalytics that allows attackers to read arbitrary files on the system by manipulating ...
Jan 3, 2024This path traversal vulnerability in MLflow allows attackers to read arbitrary files on the server by manipulating file paths in requests. It affects ...
Dec 13, 2023This vulnerability allows authenticated attackers to upload arbitrary files, including ASP/ASPX web shells, to the web root directory of IDAttend's ID...
Oct 25, 2023This vulnerability allows authenticated remote attackers to upload arbitrary files to any location on the AgeVolt Portal server through directory trav...
Oct 25, 2023This vulnerability in Cambium Enterprise Wi-Fi System Software allows attackers to execute arbitrary commands on affected devices by exploiting improp...
Sep 29, 2023This CVE describes a directory traversal vulnerability in itechyou dreamer CMS v4.1.3 that allows remote attackers to execute arbitrary code by manipu...
Sep 25, 2023This path traversal vulnerability in SHIRASAGI CMS allows authenticated attackers to manipulate server files by exploiting improper path validation. A...
Sep 5, 2023About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free