CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,131
Total CVEs
503
Critical
1,086
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Fedoraproject 17
5 Solarwinds 17
6 Fortinet 16
7 Samsung 16
8 Debian 16
9 Adobe 15
10 Siemens 15

All Path Traversal CVEs (2,131)

CVE-2020-13377
8.1

This vulnerability allows authenticated low-privileged attackers to perform directory traversal attacks through the web-services interface of Loadbala...

May 12, 2023
CVE-2023-27700
8.1

MuYuCMS v2.2 contains an arbitrary file deletion vulnerability in the /accessory/picdel.html component that allows attackers to delete any file on the...

Mar 28, 2023
CVE-2023-0454
8.1

OrangeScrum version 2.0.11 contains a path traversal vulnerability that allows authenticated attackers to delete arbitrary files on the server. This o...

Feb 1, 2023
CVE-2022-0902
8.1

This CVE combines path traversal and command injection vulnerabilities in ABB flow computer and remote controller products. Attackers can exploit thes...

Jul 21, 2022
CVE-2022-1993
8.1

CVE-2022-1993 is a path traversal vulnerability in Gogs (Go Git Service) that allows attackers to read arbitrary files on the server by manipulating f...

Jun 9, 2022
CVE-2021-40668
8.1

This path traversal vulnerability in Android HTTP File Server 1.4.1 allows attackers to access, list, and modify files outside the intended directory....

Jun 9, 2022
CVE-2022-1850
8.1

CVE-2022-1850 is a path traversal vulnerability in FileGator that allows attackers to access files outside the intended directory. This affects all Fi...

May 24, 2022
CVE-2022-28058
8.1

Verydows v2.0 contains an arbitrary file deletion vulnerability in the backend file controller that allows attackers to delete files on the server. Th...

Apr 26, 2022
CVE-2022-28523
8.1

HongCMS 3.0.0 contains an arbitrary file deletion vulnerability in the template management component. Attackers can delete any file on the server by e...

Apr 26, 2022
CVE-2022-28527
8.1

CVE-2022-28527 is an arbitrary folder deletion vulnerability in dhcms v20170919 that allows attackers to delete arbitrary folders via the /admin.php?r...

Apr 26, 2022
CVE-2021-40680
8.1

This vulnerability allows attackers to perform directory traversal attacks on Artica Proxy by manipulating the filename parameter in the /cgi-bin/main...

Apr 25, 2022
CVE-2022-24851
8.1

CVE-2022-24851 is a stored cross-site scripting (XSS) vulnerability in LDAP Account Manager (LAM) that allows authenticated attackers to inject malici...

Apr 15, 2022
CVE-2022-23971
8.1

This vulnerability allows unauthenticated attackers on the local network to perform path traversal attacks on ASUS RT-AX56U routers. By exploiting ins...

Apr 7, 2022
CVE-2021-26601
8.1

CVE-2021-26601 is a path traversal vulnerability in ImpressCMS that allows attackers to read arbitrary files on the server by manipulating the image_t...

Mar 28, 2022
CVE-2022-23107
8.1

The Jenkins Warnings Next Generation Plugin vulnerability allows attackers with Item/Configure permission to read and write files with specific hard-c...

Jan 12, 2022
CVE-2021-21909
8.1

CVE-2021-21909 is a path traversal vulnerability in a file deletion command that allows arbitrary file deletion via specially crafted arguments. Attac...

Dec 22, 2021
CVE-2021-40153
8.1

This vulnerability in Squashfs-Tools allows directory traversal attacks during archive extraction. Attackers can craft malicious squashfs archives tha...

Aug 27, 2021
CVE-2021-24010
8.1

This CVE describes a path traversal vulnerability in FortiSandbox that allows authenticated users to access restricted files and directories via speci...

Aug 4, 2021
CVE-2021-37443
8.1

CVE-2021-37443 is a path traversal vulnerability in NCH IVM Attendant that allows attackers to delete arbitrary files on the server via the logdeletes...

Jul 25, 2021
CVE-2021-37447
8.1

This vulnerability allows authenticated users in NCH Quorum conference software to delete arbitrary files via directory traversal in the documentdelet...

Jul 25, 2021
CVE-2020-24146
8.1

This vulnerability allows authorized WordPress users to perform directory traversal attacks via the CM Download Manager plugin, enabling them to delet...

Jul 7, 2021
CVE-2021-29492
8.1

Envoy proxy versions 1.18.2 and earlier fail to decode escaped slash sequences (%2F and %5C) in HTTP URL paths, allowing attackers to bypass access co...

May 28, 2021
CVE-2020-21057
8.1

This CVE describes a directory traversal vulnerability in FusionPBX 4.5.7 that allows authenticated remote attackers to delete arbitrary folders on th...

May 20, 2021
CVE-2021-20661
8.1

This directory traversal vulnerability in SolarView Compact SV-CPT-MC310 allows authenticated attackers to delete arbitrary files and directories on t...

Feb 24, 2021
CVE-2020-28374
8.1

This vulnerability allows remote attackers with access to an iSCSI LUN to perform directory traversal attacks via XCOPY requests in the Linux kernel's...

Jan 13, 2021
CVE-2020-5804
8.1

This path traversal vulnerability in Marvell QConvergeConsole GUI allows authenticated remote attackers to delete arbitrary files with SYSTEM/root pri...

Jan 8, 2021
CVE-2020-27385
8.1

This vulnerability allows authenticated attackers to read and write files outside the web root directory using directory traversal techniques in FlexD...

Nov 12, 2020
CVE-2020-3550
8.1

This vulnerability allows authenticated remote attackers to perform directory traversal attacks on Cisco Firepower Management Center (FMC) and Firepow...

Oct 21, 2020
CVE-2026-23535
8.0

This vulnerability in the Weblate command-line client (wlc) allows a malicious Weblate server to write files to arbitrary locations on a client's syst...

Jan 16, 2026
CVE-2025-12638
8.0

This CVE describes a path traversal vulnerability in Keras 3.11.3's keras.utils.get_file() function when extracting tar archives. The vulnerability al...

Nov 28, 2025
CVE-2025-9079
8.0

This vulnerability allows admin users in Mattermost to execute arbitrary code by uploading malicious plugins to the prepackaged plugins directory. The...

Sep 19, 2025
CVE-2025-9693
8.0

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to delete arbitrary files on the server due to insuffic...

Sep 11, 2025
CVE-2024-31232
8.0

This vulnerability allows attackers to perform path traversal attacks in the Rehub WordPress theme, enabling local file inclusion of PHP files. It aff...

May 17, 2024
CVE-2023-5938
8.0

This vulnerability allows attackers to perform path traversal attacks via malicious ZIP archives ('zip slip'), enabling arbitrary file overwrites on t...

May 15, 2024
CVE-2023-5123
8.0

The JSON datasource plugin for Grafana has a path traversal vulnerability that allows authenticated users to query arbitrary endpoints on the configur...

Feb 14, 2024
CVE-2023-40055
8.0

This vulnerability allows low-privileged users to exploit directory traversal in SolarWinds Network Configuration Manager to execute arbitrary code wi...

Nov 9, 2023
CVE-2023-33226
8.0

This vulnerability in SolarWinds Network Configuration Manager allows low-privileged users to exploit directory traversal flaws to execute arbitrary c...

Nov 1, 2023
CVE-2021-42542
8.0

This directory traversal vulnerability allows attackers to access files outside the intended backup folder structure by manipulating path sequences. I...

Oct 22, 2021
CVE-2020-14352
8.0

CVE-2020-14352 is a directory traversal vulnerability in librepo versions before 1.12.1 that allows attackers controlling remote repositories to write...

Aug 30, 2020
CVE-2022-31159
7.9

A partial-path traversal vulnerability in AWS SDK for Java v1 allows attackers to write S3 bucket contents outside the intended destination directory ...

Jul 15, 2022
CVE-2021-33183
7.9

This path traversal vulnerability in Synology Docker's container volume management allows local users to bypass directory restrictions and access arbi...

Jun 1, 2021
CVE-2026-28518
7.8

OpenViking versions 0.2.1 and earlier contain a path traversal vulnerability in .ovpack import handling that allows attackers to write arbitrary files...

Mar 3, 2026
CVE-2026-20615
7.8

A path validation vulnerability in Apple operating systems allows malicious applications to gain root privileges through improper path handling. This ...

Feb 11, 2026
CVE-2026-20614
7.8

This CVE describes a path handling vulnerability in macOS that allows an application to gain root privileges through improper validation. It affects m...

Feb 11, 2026
CVE-2026-0651
7.8

This vulnerability allows attackers on the same local network to probe the TP-Link Tapo C260 v1 camera's filesystem to determine if specific files exi...

Feb 10, 2026
CVE-2025-11002
7.8

A directory traversal vulnerability in 7-Zip's ZIP file parsing allows remote attackers to execute arbitrary code by crafting malicious ZIP archives c...

Jan 23, 2026
CVE-2026-20613
7.8

This vulnerability allows arbitrary file write through path traversal in archive extraction functions. Attackers can place malicious archives that ext...

Jan 23, 2026
CVE-2025-68921
7.8

CVE-2025-68921 is a directory traversal vulnerability in SteelSeries Nahimic 3 audio software that allows attackers to read arbitrary files on the sys...

Jan 16, 2026
CVE-2025-14420
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pdfforge PDF Architect by tricking user...

Dec 23, 2025
CVE-2025-14413
7.8

This vulnerability allows remote attackers to execute arbitrary code on Soda PDF Desktop by tricking users into opening malicious CBZ files. Attackers...

Dec 23, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,131 CVEs classified as CWE-22, with 503 rated critical and 1,086 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free