CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,136
Total CVEs
506
Critical
1,088
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Samsung 16
8 Debian 16
9 Adobe 15
10 Siemens 15

All Path Traversal CVEs (2,136)

CVE-2025-68921
7.8

CVE-2025-68921 is a directory traversal vulnerability in SteelSeries Nahimic 3 audio software that allows attackers to read arbitrary files on the sys...

Jan 16, 2026
CVE-2025-14420
7.8

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of pdfforge PDF Architect by tricking user...

Dec 23, 2025
CVE-2025-14413
7.8

This vulnerability allows remote attackers to execute arbitrary code on Soda PDF Desktop by tricking users into opening malicious CBZ files. Attackers...

Dec 23, 2025
CVE-2025-67488
7.8

This ZipSlip vulnerability in SiYuan personal knowledge management software allows authenticated users to overwrite arbitrary files on the system thro...

Dec 9, 2025
CVE-2025-54160
7.8

This path traversal vulnerability in Synology BeeDrive desktop software allows local users to execute arbitrary code by manipulating file paths. It af...

Dec 4, 2025
CVE-2025-11001
7.8

This vulnerability in 7-Zip allows remote attackers to execute arbitrary code by exploiting directory traversal through specially crafted ZIP files co...

Nov 19, 2025
CVE-2025-63408
7.8

Local Agent DVR versions through 6.6.1.0 contain a directory traversal vulnerability that allows unauthenticated local attackers to access sensitive f...

Nov 18, 2025
CVE-2025-54658
7.8

This path traversal vulnerability in Fortinet FortiDLP Agent's Outlookproxy plugin allows authenticated attackers on affected MacOS systems to escalat...

Oct 16, 2025
CVE-2025-8406
7.8

ZenML version 0.83.1 contains a path traversal vulnerability in the PathMaterializer class that allows attackers to write arbitrary files during data....

Oct 5, 2025
CVE-2025-7975
7.8

This vulnerability allows remote attackers to execute arbitrary code on Anritsu ShockLine systems by tricking users into opening malicious CHX files. ...

Sep 2, 2025
CVE-2024-56179
7.8

This vulnerability allows attackers to write files to arbitrary directories on Windows systems via directory traversal when victims open malicious Min...

Aug 22, 2025
CVE-2025-8941
7.8

This vulnerability in the linux-pam pam_namespace module allows local users to exploit symlink attacks and race conditions to elevate their privileges...

Aug 13, 2025
CVE-2025-43196
7.8

This CVE describes a path handling vulnerability in macOS that allows an application to gain root privileges through improper validation. It affects m...

Jul 30, 2025
CVE-2025-6218
KEV 7.8

This vulnerability in WinRAR allows attackers to execute arbitrary code by tricking users into opening malicious archive files containing specially cr...

Jun 21, 2025
CVE-2025-0332
7.8

This vulnerability in Progress Telerik UI for WinForms allows attackers to perform path traversal attacks during archive decompression, potentially wr...

Feb 12, 2025
CVE-2025-0542
7.8

This vulnerability allows local unprivileged attackers to escalate privileges to SYSTEM level on G DATA Management Server installations. Attackers can...

Jan 25, 2025
CVE-2024-54489
7.8

A path handling vulnerability in macOS mount command allows arbitrary code execution when processing malicious input. This affects macOS systems befor...

Dec 12, 2024
CVE-2024-7565
7.8

This vulnerability allows remote attackers to execute arbitrary code on SMARTBEAR SoapUI installations through directory traversal in the unpackageAll...

Nov 22, 2024
CVE-2024-34787
7.8

This CVE describes a path traversal vulnerability in Ivanti Endpoint Manager that allows a local unauthenticated attacker to execute arbitrary code. U...

Nov 13, 2024
CVE-2024-46954
7.8

A directory traversal vulnerability in Ghostscript's UTF-8 decoder allows attackers to escape directory restrictions via specially crafted overlong UT...

Nov 10, 2024
CVE-2024-44255
7.8

This vulnerability allows a malicious app to execute arbitrary shortcuts without user consent on Apple devices. It affects multiple Apple operating sy...

Oct 28, 2024
CVE-2024-47027
7.8

This vulnerability allows local attackers to access arbitrary physical memory due to improper input validation in Android's shared memory component. I...

Oct 25, 2024
CVE-2024-9675
7.8

This vulnerability in Buildah allows attackers to bypass path validation in cache mounts, enabling arbitrary host directory access during container bu...

Oct 9, 2024
CVE-2024-7262
7.8

This vulnerability allows attackers to load arbitrary Windows libraries through improper path validation in WPS Office's promecefpluginhost.exe compon...

Aug 15, 2024
CVE-2024-7248
7.8

This vulnerability in Comodo Internet Security Pro allows local attackers to escalate privileges from low-privileged user accounts to SYSTEM level by ...

Jul 29, 2024
CVE-2023-44451
7.8

This vulnerability in Linux Mint's Xreader EPUB parser allows remote attackers to execute arbitrary code by tricking users into opening malicious EPUB...

May 3, 2024
CVE-2023-39506
7.8

PDF-XChange Editor has a directory traversal vulnerability in the createDataObject method that allows remote attackers to execute arbitrary code. Atta...

May 3, 2024
CVE-2023-39459
7.8

This vulnerability in Triangle MicroWorks SCADA Data Gateway allows remote attackers to create arbitrary files on affected systems by exploiting direc...

May 3, 2024
CVE-2024-23773
7.8

This vulnerability allows local attackers with access to a Windows system to delete any file with SYSTEM privileges through the KSchedulerSvc.exe comp...

Apr 30, 2024
CVE-2022-45792
7.8

This vulnerability in Omron PLC engineering software allows attackers to craft malicious project files that exploit directory traversal to write arbit...

Jan 22, 2024
CVE-2024-21633
7.8

CVE-2024-21633 is a path traversal vulnerability in Apktool that allows attackers to write files to arbitrary locations on the system where Apktool ru...

Jan 3, 2024
CVE-2023-36123
7.8

This CVE describes a directory traversal vulnerability in Hex-Dragon Plain Craft Launcher 2 Alpha 1.3.9 that allows local attackers to execute arbitra...

Oct 7, 2023
CVE-2023-43825
7.8

A relative path traversal vulnerability in Shihonkanri Plus allows local attackers to execute arbitrary code by tricking legitimate users into importi...

Sep 27, 2023
CVE-2023-35670
7.8

This vulnerability allows local attackers to write files to other apps' private directories on Android devices through a path traversal flaw in MediaP...

Sep 11, 2023
CVE-2021-35980
7.8

This path traversal vulnerability in Adobe Acrobat Reader DC allows attackers to execute arbitrary code by tricking users into opening malicious PDF f...

Sep 6, 2023
CVE-2023-39139
7.8

CVE-2023-39139 is a path traversal vulnerability in Archive v3.3.7 that allows attackers to write arbitrary files outside the intended extraction dire...

Aug 30, 2023
CVE-2023-39135
7.8

CVE-2023-39135 is a path traversal vulnerability in Zip Swift library v2.1.2 that allows attackers to write files outside the intended extraction dire...

Aug 30, 2023
CVE-2023-39810
7.8

A directory traversal vulnerability in BusyBox's cpio command allows attackers to write files outside the intended extraction directory. This affects ...

Aug 28, 2023
CVE-2023-37646
7.8

This vulnerability in Bitberry File Opener v23.0 allows attackers to perform directory traversal attacks through CAB file extraction. Attackers can wr...

Aug 8, 2023
CVE-2023-31427
7.8

This vulnerability allows authenticated local users on Brocade Fabric OS to execute arbitrary commands regardless of their assigned privileges by expl...

Aug 1, 2023
CVE-2023-25307
7.8

CVE-2023-25307 is a directory traversal vulnerability in nothub mrpack-install versions up to v0.16.2 that allows attackers to write files outside the...

Jun 26, 2023
CVE-2023-33747
7.8

CloudPanel v2.2.2 contains a path traversal vulnerability that allows attackers to access files outside the intended directory. This affects all syste...

Jun 6, 2023
CVE-2023-27981
7.8

This vulnerability allows remote code execution through path traversal in Schneider Electric's IGSS software. An attacker can craft a malicious report...

Mar 21, 2023
CVE-2022-47506
7.8

CVE-2022-47506 is a directory traversal vulnerability in SolarWinds Platform that allows authenticated local attackers to modify default configuration...

Feb 15, 2023
CVE-2021-41031
7.8

A local privilege escalation vulnerability in FortiClient for Windows allows unprivileged local attackers to gain SYSTEM-level privileges by exploitin...

Jul 18, 2022
CVE-2022-20220
7.8

This vulnerability allows local attackers to bypass file permissions through a path traversal error in Android's CallLogProvider component. It enables...

Jul 13, 2022
CVE-2021-22797
7.8

This path traversal vulnerability in Schneider Electric's industrial control software allows attackers to deploy malicious scripts to unauthorized loc...

Apr 13, 2022
CVE-2022-21999
7.8

This vulnerability allows attackers to gain SYSTEM-level privileges on Windows systems by exploiting the Print Spooler service. It affects Windows ser...

Feb 9, 2022
CVE-2021-40724
7.8

A path traversal vulnerability in Adobe Acrobat Reader for Android allows attackers to execute arbitrary code by tricking users into opening malicious...

Oct 15, 2021
CVE-2021-41579
7.8

This vulnerability in LCDS LAquis SCADA allows attackers to bypass security controls and write arbitrary files to the operating system through path tr...

Oct 4, 2021

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,136 CVEs classified as CWE-22, with 506 rated critical and 1,088 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free