CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,146
Total CVEs
506
Critical
1,098
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,146)

CVE-2025-67160
7.5

This directory traversal vulnerability in Vatilon v1.12.37-20240124 allows attackers to access sensitive files and directories outside the intended we...

Jan 2, 2026
CVE-2025-59384
7.5

A path traversal vulnerability in Qfiling allows remote attackers to read arbitrary files on the system by manipulating file paths. This affects all Q...

Jan 2, 2026
CVE-2022-50792
7.5

This vulnerability allows remote attackers to read arbitrary files on SOUND4 IMPACT/FIRST/PULSE/Eco devices without authentication by manipulating the...

Dec 30, 2025
CVE-2024-25183
7.5

CVE-2024-25183 is a directory traversal vulnerability in givanz VvvebJs 1.7.2 that allows attackers to read arbitrary files on the server via the scan...

Dec 29, 2025
CVE-2025-67254
7.5

NagiosXI 2026R1.0.1 build 1762361101 contains a directory traversal vulnerability in /admin/coreconfigsnapshots.php that allows attackers to access fi...

Dec 29, 2025
CVE-2023-53962
7.5

CVE-2023-53962 is an unauthenticated directory traversal vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x that allows remote attackers to write arb...

Dec 22, 2025
CVE-2025-11540
7.5

A path traversal vulnerability in Sharp Display Solutions projectors allows attackers to read arbitrary files on the device's filesystem. This affects...

Dec 22, 2025
CVE-2025-66905
7.5

CVE-2025-66905 is a path traversal vulnerability in the Takes web framework that allows remote attackers to read arbitrary files from the host system ...

Dec 19, 2025
CVE-2025-64230
7.5

This path traversal vulnerability in the WP Chill Filr WordPress plugin allows attackers to delete arbitrary files on the server. It affects all WordP...

Dec 18, 2025
CVE-2025-67171
7.5

This directory traversal vulnerability in RiteCMS v3.1.0 allows attackers to bypass access controls and read sensitive files on the server. Attackers ...

Dec 17, 2025
CVE-2025-67174
7.5

This CVE describes a local file inclusion vulnerability in RiteCMS v3.1.0 that allows attackers to read arbitrary files on the server through director...

Dec 17, 2025
CVE-2025-68155
7.5

This vulnerability in @vitejs/plugin-rsc allows unauthenticated attackers to read arbitrary files accessible to the Node.js process during development...

Dec 16, 2025
CVE-2024-58312
7.5

CVE-2024-58312 is an unauthenticated path traversal vulnerability in xbtitFM 4.1.18 that allows attackers to read sensitive system files by manipulati...

Dec 11, 2025
CVE-2025-56430
7.5

This CVE describes a directory traversal vulnerability in FearlessCMS that allows remote attackers to delete arbitrary directories via the plugin-hand...

Dec 10, 2025
CVE-2025-56431
7.5

This directory traversal vulnerability in FearlessCMS allows remote attackers to use the plugin-handler.php file with the file_get_contents() function...

Dec 10, 2025
CVE-2025-34395
7.5

This vulnerability in Barracuda Service Center allows unauthenticated attackers to read arbitrary files via path traversal in a .NET Remoting service....

Dec 10, 2025
CVE-2025-13339
7.5

The Hippoo Mobile App for WooCommerce WordPress plugin has a path traversal vulnerability that allows unauthenticated attackers to read arbitrary file...

Dec 10, 2025
CVE-2025-66645
7.5

This directory traversal vulnerability in NiceGUI allows remote attackers to read arbitrary files on the server filesystem by exploiting the App.add_m...

Dec 9, 2025
CVE-2023-53772
7.5

MiniDVBLinux 5.4 contains an arbitrary file disclosure vulnerability that allows unauthenticated attackers to read sensitive system files through the ...

Dec 9, 2025
CVE-2025-65878
7.5

The warehouse management system version 1.2 contains an arbitrary file read vulnerability via directory traversal. Attackers can exploit the /file/sho...

Dec 5, 2025
CVE-2025-65838
7.5

PublicCMS V5.202506.b contains a path traversal vulnerability in the doUploadSitefile method that allows attackers to write arbitrary files to uninten...

Dec 1, 2025
CVE-2025-63371
7.5

OneCommander 3.102.0.0 contains a directory traversal vulnerability in its ZIP file processing component that allows attackers to write files outside ...

Nov 19, 2025
CVE-2025-60574
7.5

A Local File Inclusion vulnerability in tQuadra CMS 4.2.1117 allows attackers to read arbitrary files from the server by exploiting improper input san...

Nov 7, 2025
CVE-2025-57698
7.5

AstrBot Project v3.5.22 contains a directory traversal vulnerability in the plugin upload interface. Attackers can upload files to arbitrary locations...

Nov 7, 2025
CVE-2025-59171
7.5

This vulnerability allows attackers to upload malicious configuration files that bypass directory traversal protections, leading to remote code execut...

Nov 6, 2025
CVE-2025-60242
7.5

This path traversal vulnerability in the WordPress Download Counter plugin allows attackers to download arbitrary files from the server by manipulatin...

Nov 6, 2025
CVE-2025-50735
7.5

A directory traversal vulnerability in NextChat's WebDAV proxy allows attackers to access sensitive files outside the intended directory by exploiting...

Nov 3, 2025
CVE-2025-3355
7.5

CVE-2025-3355 is a directory traversal vulnerability in IBM Tivoli Monitoring that allows remote attackers to read arbitrary files on the system by se...

Oct 30, 2025
CVE-2025-12055
EPSS 37.2% 7.5

This vulnerability allows unauthenticated attackers to read arbitrary files from the Windows operating system on affected MPDV Mikrolab systems. It af...

Oct 27, 2025
CVE-2025-62254
7.5

This vulnerability in Liferay Portal and DXP allows remote attackers to trigger denial of service attacks by exploiting the ComboServlet's lack of lim...

Oct 23, 2025
CVE-2025-34518
7.5

CVE-2025-34518 is a relative path traversal vulnerability in Ilevia EVE X1 Server firmware that allows attackers to read arbitrary files on the system...

Oct 16, 2025
CVE-2025-61884
KEV EPSS 40.2% 7.5

This is a path traversal vulnerability (CWE-22) in Oracle Configurator within Oracle E-Business Suite that allows unauthenticated attackers to access ...

Oct 12, 2025
CVE-2025-59744
7.5

This path traversal vulnerability in AndSoft's e-TMS v25.03 allows attackers to access files within the web root directory by manipulating the 'docurl...

Oct 2, 2025
CVE-2025-10468
7.5

This path traversal vulnerability in Beyaz Computer CityPlus allows attackers to access files outside the intended directory by manipulating file path...

Sep 19, 2025
CVE-2025-58072
7.5

A path traversal vulnerability in SS1 Ver.16.0.0.10 and earlier allows remote unauthenticated attackers to view arbitrary files on the system. This af...

Aug 28, 2025
CVE-2025-29420
7.5

PerfreeBlog v4.0.11 contains a directory traversal vulnerability in the getThemeFilesByName function that allows attackers to read arbitrary files on ...

Aug 25, 2025
CVE-2025-54021
7.5

This path traversal vulnerability in Simple File List WordPress plugin allows attackers to download arbitrary files from the server by manipulating fi...

Aug 20, 2025
CVE-2025-7641
7.5

The Assistant for NextGEN Gallery WordPress plugin has an unauthenticated directory deletion vulnerability in its REST API endpoint. Attackers can del...

Aug 15, 2025
CVE-2025-25231
7.5

Omnissa Workspace ONE UEM contains a path traversal vulnerability in secondary context paths that allows attackers to access restricted API endpoints ...

Aug 11, 2025
CVE-2025-54141
7.5

This CVE describes a directory traversal vulnerability in ViewVC's standalone.py script that allows attackers to read arbitrary files from the host se...

Jul 22, 2025
CVE-2025-49656
7.5

This vulnerability allows administrators in Apache Jena Fuseki to create database files outside the designated files area, potentially enabling path t...

Jul 21, 2025
CVE-2015-10134
EPSS 50.3% 7.5

The Simple Backup WordPress plugin allows attackers to download any file from the server without authentication due to missing security checks. This a...

Jul 19, 2025
CVE-2025-27210
7.5

This vulnerability is an incomplete fix for CVE-2025-23084 in Node.js that allows path traversal attacks when using Windows device names like CON, PRN...

Jul 18, 2025
CVE-2025-31070
7.5

This path traversal vulnerability in the LambertGroup HTML5 Radio Player - WPBakery Page Builder Addon WordPress plugin allows attackers to download a...

Jul 16, 2025
CVE-2025-28955
7.5

This path traversal vulnerability in the Easy Video Player WordPress & WooCommerce plugin allows attackers to download arbitrary files from the server...

Jul 16, 2025
CVE-2025-6804
EPSS 15.6% 7.5

This vulnerability allows unauthenticated remote attackers to perform directory traversal attacks on Marvell QConvergeConsole installations. Attackers...

Jul 7, 2025
CVE-2025-6807
7.5

This vulnerability allows remote attackers to read sensitive files on Marvell QConvergeConsole installations without authentication. Attackers can exp...

Jul 7, 2025
CVE-2025-6797
EPSS 15.6% 7.5

This vulnerability allows unauthenticated remote attackers to read arbitrary files on Marvell QConvergeConsole installations via directory traversal. ...

Jul 7, 2025
CVE-2025-6800
EPSS 15.6% 7.5

This vulnerability allows unauthenticated remote attackers to read arbitrary files on systems running Marvell QConvergeConsole. Attackers can exploit ...

Jul 7, 2025
CVE-2025-6795
7.5

This vulnerability allows unauthenticated remote attackers to perform directory traversal attacks on Marvell QConvergeConsole installations. By exploi...

Jul 7, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free