CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,995
Total CVEs
447
Critical
1,009
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (1,995)

CVE-2025-27142
8.8

LocalSend versions before 1.17.0 have a path traversal vulnerability in file upload endpoints that allows attackers to write files to arbitrary locati...

Feb 25, 2025
CVE-2025-22130
8.8

CVE-2025-22130 is a path traversal vulnerability in Soft Serve Git server that allows non-admin users to access and take over other users' repositorie...

Jan 8, 2025
CVE-2024-55587
8.8

This vulnerability in python-libarchive allows attackers to perform directory traversal attacks when extracting ZIP archives, potentially writing file...

Dec 12, 2024
CVE-2024-44625
8.8

This directory traversal vulnerability in Gogs allows attackers to read, write, or delete arbitrary files on the server by manipulating file paths in ...

Nov 15, 2024
CVE-2024-37847
8.8

This vulnerability allows attackers to upload malicious files to MangoOS and Mango API systems, potentially leading to remote code execution. It affec...

Oct 25, 2024
CVE-2024-35308
8.8

This vulnerability allows authenticated attackers to read arbitrary files on Pandora FMS servers through the plugin edition feature. It affects Pandor...

Oct 22, 2024
CVE-2024-33369
8.8

A directory traversal vulnerability in Plasmoapp RPShare Fabric mod v1.0.0 allows remote attackers to read arbitrary files on the server by manipulati...

Sep 27, 2024
CVE-2024-7149
8.8

This vulnerability allows authenticated WordPress users with Contributor-level access or higher to perform Local File Inclusion attacks in the Eventin...

Sep 27, 2024
CVE-2024-7145
8.8

The JetElements WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level access or hi...

Aug 16, 2024
CVE-2024-7146
8.8

The JetTabs for Elementor WordPress plugin contains a Local File Inclusion vulnerability that allows authenticated attackers with Contributor-level ac...

Aug 16, 2024
CVE-2024-7399
8.8

This vulnerability allows attackers to write arbitrary files with system-level privileges on Samsung MagicINFO 9 Server by exploiting improper pathnam...

Aug 12, 2024
CVE-2024-6707
8.8

This CVE describes a path traversal vulnerability that allows attackers to upload malicious files to arbitrary locations on the web server's filesyste...

Aug 7, 2024
CVE-2024-5709
8.8

The WPBakery Visual Composer plugin for WordPress has a Local File Inclusion vulnerability that allows authenticated attackers with Author-level permi...

Aug 6, 2024
CVE-2024-24320
8.8

This directory traversal vulnerability in Mgt-commerce CloudPanel allows authenticated attackers to read arbitrary files and execute code via the serv...

Jun 14, 2024
CVE-2024-5187
8.8

A path traversal vulnerability in ONNX framework's download_model_with_test_data function allows attackers to overwrite arbitrary system files via mal...

Jun 6, 2024
CVE-2024-0520
8.8

This CVE allows remote code execution in MLflow versions before 2.9.0 due to command injection vulnerability. Attackers can manipulate file paths when...

Jun 6, 2024
CVE-2024-5505
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code with SYSTEM privileges on NETGEAR ProSAFE Network Management System...

Jun 6, 2024
CVE-2024-5179
8.8

The Cowidgets – Elementor Addons WordPress plugin contains a Local File Inclusion vulnerability in all versions up to 1.1.1. Authenticated attackers...

Jun 6, 2024
CVE-2024-37032
8.8

This vulnerability in Ollama allows attackers to bypass path validation when retrieving model files, potentially leading to arbitrary file read or rem...

May 31, 2024
CVE-2024-34060
8.8

CVE-2024-34060 is an arbitrary file write vulnerability in IrisEVTXModule that allows attackers to write malicious files to the server during EVTX fil...

May 23, 2024
CVE-2023-51599
8.8

This vulnerability in Honeywell Saia PG5 Controls Suite allows remote attackers to execute arbitrary code by exploiting a directory traversal flaw in ...

May 3, 2024
CVE-2023-51603
8.8

This vulnerability in Honeywell Saia PG5 Controls Suite allows remote attackers to execute arbitrary code by tricking users into opening malicious CAB...

May 3, 2024
CVE-2023-50233
8.8

This vulnerability allows remote attackers to execute arbitrary code on Inductive Automation Ignition installations by exploiting a directory traversa...

May 3, 2024
CVE-2023-42130
8.8

This vulnerability in A10 Thunder ADC allows authenticated remote attackers to read and delete arbitrary files on the system through directory travers...

May 3, 2024
CVE-2023-41182
8.8

This vulnerability in NETGEAR ProSAFE Network Management System allows authenticated attackers to bypass authentication and execute arbitrary code wit...

May 3, 2024
CVE-2024-34033
8.8

Delta Electronics DIAEnergie software has a path traversal vulnerability that allows attackers to write files outside intended directories, potentiall...

May 3, 2024
CVE-2024-32258
8.8

CVE-2024-32258 is a path traversal vulnerability in fceux 2.7.0's network server that allows unauthenticated attackers to overwrite arbitrary files on...

Apr 23, 2024
CVE-2024-27976
8.8

This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to execute arbitrary commands with SYSTEM ...

Apr 19, 2024
CVE-2024-25000
8.8

This path traversal vulnerability in Ivanti Avalanche's web component allows authenticated remote attackers to execute arbitrary commands with SYSTEM ...

Apr 19, 2024
CVE-2024-24992
8.8

This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It a...

Apr 19, 2024
CVE-2024-24994
8.8

This path traversal vulnerability in Ivanti Avalanche allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges. It a...

Apr 19, 2024
CVE-2024-1974
8.8

This vulnerability in the HT Mega plugin for WordPress allows authenticated attackers with contributor-level access or higher to perform directory tra...

Apr 9, 2024
CVE-2024-27921
8.8

Grav CMS versions before 1.7.45 contain a file upload path traversal vulnerability that allows attackers to upload malicious files to arbitrary locati...

Mar 21, 2024
CVE-2024-21677
8.8

This is a high-severity path traversal vulnerability (CWE-22) in Confluence Data Center and Server that allows unauthenticated attackers to access or ...

Mar 19, 2024
CVE-2024-24042
8.8

A directory traversal vulnerability in Devan-Kerman ARRP v0.8.1 and earlier allows remote attackers to execute arbitrary code via the dumpDirect funct...

Mar 19, 2024
CVE-2024-27771
8.8

CVE-2024-27771 is a path traversal vulnerability in Unitronics Unistream Unilogic software that could allow remote code execution. Attackers can explo...

Mar 18, 2024
CVE-2024-1358
8.8

The Elementor Addon Elements WordPress plugin has a directory traversal vulnerability in its render function. Authenticated attackers with contributor...

Mar 13, 2024
CVE-2024-21891
8.8

This vulnerability allows attackers to bypass Node.js's experimental permission model by overwriting built-in path normalization functions, enabling p...

Feb 20, 2024
CVE-2024-22514
8.8

CVE-2024-22514 is a path traversal vulnerability in iSpyConnect.com Agent DVR that allows attackers to execute arbitrary files by restoring a maliciou...

Feb 6, 2024
CVE-2024-22779
8.8

This CVE describes a directory traversal vulnerability in Kihron ServerRPExposer v1.0.2 and earlier that allows remote attackers to execute arbitrary ...

Feb 2, 2024
CVE-2024-21852
8.8

CVE-2024-21852 is a Zip Slip vulnerability in Rapid SCADA that allows attackers to upload malicious configuration files during unpacking, leading to a...

Feb 1, 2024
CVE-2024-23768
8.8

This CVE describes an improper path traversal vulnerability in Dremio that allows authenticated users with limited folder access to bypass authorizati...

Jan 22, 2024
CVE-2021-24566
8.8

The WooCommerce Currency Switcher FOX WordPress plugin before version 1.3.7 contains a Local File Inclusion (LFI) vulnerability via the 'woocs' shortc...

Jan 16, 2024
CVE-2023-45722
8.8

CVE-2023-45722 is a path traversal vulnerability in HCL DRYiCE MyXalytics that allows attackers to read arbitrary files on the system by manipulating ...

Jan 3, 2024
CVE-2023-6753
8.8

This path traversal vulnerability in MLflow allows attackers to read arbitrary files on the server by manipulating file paths in requests. It affects ...

Dec 13, 2023
CVE-2023-26578
8.8

This vulnerability allows authenticated attackers to upload arbitrary files, including ASP/ASPX web shells, to the web root directory of IDAttend's ID...

Oct 25, 2023
CVE-2022-38484
8.8

This vulnerability allows authenticated remote attackers to upload arbitrary files to any location on the AgeVolt Portal server through directory trav...

Oct 25, 2023
CVE-2022-35908
8.8

This vulnerability in Cambium Enterprise Wi-Fi System Software allows attackers to execute arbitrary commands on affected devices by exploiting improp...

Sep 29, 2023
CVE-2023-43382
8.8

This CVE describes a directory traversal vulnerability in itechyou dreamer CMS v4.1.3 that allows remote attackers to execute arbitrary code by manipu...

Sep 25, 2023
CVE-2023-39448
8.8

This path traversal vulnerability in SHIRASAGI CMS allows authenticated attackers to manipulate server files by exploiting improper path validation. A...

Sep 5, 2023

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free