CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,146)
This vulnerability allows unauthenticated attackers to read arbitrary files from a specific directory in Zimbra Collaboration Suite. It affects Zimbra...
Aug 12, 2024An unauthenticated directory traversal vulnerability in Vonets industrial wifi bridge devices allows remote attackers to read arbitrary files and bypa...
Aug 12, 2024CVE-2024-6781 is a path traversal vulnerability in Calibre ebook management software that allows unauthenticated attackers to read arbitrary files fro...
Aug 6, 2024This CVE describes a path traversal vulnerability in Cybonet software that allows attackers to access files outside the intended directory. Attackers ...
Jul 30, 2024A path traversal vulnerability in SKYSEA Client View allows authenticated users on Windows systems to execute arbitrary executable files by manipulati...
Jul 29, 2024This vulnerability in the Ultimate Classified Listings WordPress plugin allows unauthenticated attackers to access arbitrary PHP files on the server t...
Jul 29, 2024This CVE describes a directory traversal vulnerability in Severalnines Cluster Control's CMON API that allows remote attackers to read arbitrary files...
Jul 26, 2024This vulnerability in GeoServer allows attackers to bypass input validation and read arbitrary classpath resources with specific file extensions when ...
Jul 1, 2024A path traversal vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete other users' chat histories and any .json file...
Jun 27, 2024This path traversal vulnerability in Adobe Acrobat Mobile Sign for Android allows attackers to bypass directory restrictions and access or overwrite f...
Jun 13, 2024This path traversal vulnerability in the Ovic Importer WordPress plugin allows attackers to download arbitrary files from the server by manipulating f...
Jun 10, 2024This path traversal vulnerability in the Strategery Migrations WordPress plugin allows attackers to delete arbitrary files on the server. It affects a...
Jun 10, 2024This CVE describes a local file inclusion vulnerability in gradio-app/gradio version 4.25. Attackers can exploit improper JSON parsing in the postproc...
Jun 6, 2024This path traversal vulnerability in BoldGrid Total Upkeep WordPress plugin allows attackers to download arbitrary files from the server by manipulati...
May 17, 2024CVE-2023-40297 is a directory traversal vulnerability in Stakater Forecastle that allows attackers to access files outside the intended web directory ...
May 15, 2024CmsEasy v7.7.7.9 contains a local file inclusion vulnerability in the fckedit_action method of /admin/template_admin.php that allows attackers to read...
May 7, 2024This vulnerability allows remote attackers to read arbitrary files on LG SuperSign Media Editor systems without authentication. Attackers can exploit ...
May 3, 2024This vulnerability in LG Simple Editor allows remote attackers to read sensitive files on the system without authentication. Attackers can exploit a d...
May 3, 2024This directory traversal vulnerability in ProQuality pqprintshippinglabels allows attackers to access files outside the intended directory via the mod...
Apr 30, 2024A path traversal vulnerability in MLflow allows attackers to use ';' characters in URL parameters to access unauthorized files or directories. This af...
Apr 16, 2024This path traversal vulnerability in MLflow allows attackers to read arbitrary files on the server by exploiting improper validation of the source par...
Apr 16, 2024This vulnerability allows remote attackers to perform directory traversal attacks on IBM Maximo Application Suite systems. By sending specially crafte...
Apr 6, 2024CVE-2024-27575 is an absolute path traversal vulnerability in INOTEC Sicherheitstechnik WebServer CPS220/64 version 3.3.19 that allows remote attacker...
Apr 4, 2024This vulnerability allows attackers to perform directory traversal attacks on Allied Telesis AT-S115 1.2.0 devices, enabling partial unauthorized acce...
Mar 28, 2024CVE-2024-23721 is a directory traversal vulnerability in Draytek Vigor3910 devices that allows attackers to access sensitive system files by manipulat...
Mar 20, 2024This vulnerability allows authenticated attackers to perform directory path traversal attacks in OpenClinic GA by manipulating the Page parameter in G...
Mar 19, 2024This vulnerability allows unauthenticated remote attackers to read arbitrary local files on Appwrite servers via directory traversal in the ACME-chall...
Feb 22, 2024OpenRefine versions up to 3.7.7 contain a JDBC attack vulnerability that allows attackers to read arbitrary files on the host filesystem. This occurs ...
Feb 12, 2024This vulnerability in Software FX Chart FX 7 allows attackers to perform directory traversal attacks by sending specially crafted web requests, enabli...
Feb 2, 2024A directory traversal vulnerability in LiveConfig before version 2.5.2 allows remote attackers to access sensitive files outside the intended director...
Feb 2, 2024CVE-2024-24756 is a path traversal vulnerability in Crafatar that allows attackers to read files outside the intended public directory. Affected syste...
Feb 1, 2024A directory traversal vulnerability in Qiyu iFair's uploadimage component allows remote attackers to access sensitive files outside the intended direc...
Jan 30, 2024CVE-2023-48383 is a path traversal vulnerability in NetVision airPASS that allows unauthenticated remote attackers to bypass authentication and downlo...
Jan 15, 2024CVE-2023-52288 is a directory traversal vulnerability in flaskcode versions up to 0.0.8 that allows unauthenticated attackers to read arbitrary files ...
Jan 13, 2024A directory traversal vulnerability in the SOAP Server of Atos Unify OpenScape Voice V10 allows unauthenticated remote attackers to read arbitrary fil...
Jan 12, 2024CVE-2024-22050 is a path traversal vulnerability in Iodine's static file service that allows unauthenticated remote attackers to read files outside th...
Jan 4, 2024This directory traversal vulnerability in Automatic Systems SOC FL9600 FirstLane allows remote attackers to read sensitive files on the system by mani...
Jan 3, 2024This CVE describes a directory traversal vulnerability in fuwushe.org iFair software versions 23.8_ad0 and earlier. Attackers can exploit this vulnera...
Jan 3, 2024The Backup Migration plugin for WordPress has a path traversal vulnerability that allows unauthenticated attackers to delete arbitrary files via manip...
Dec 23, 2023The MW WP Form WordPress plugin has a vulnerability allowing unauthenticated attackers to delete arbitrary files on the server, including critical Wor...
Dec 16, 2023CVE-2023-50264 is an arbitrary file read vulnerability in Bazarr subtitle management software. Attackers can read any file on the system by manipulati...
Dec 15, 2023ITPison OMICARD EDM has a path traversal vulnerability in the 'FileName' parameter that allows unauthenticated remote attackers to bypass authenticati...
Dec 15, 2023CVE-2023-48660 is an arbitrary file read vulnerability in Dell vApp Manager that allows remote attackers to read arbitrary files from the target syste...
Dec 14, 2023This vulnerability in HL7 FHIR Core Libraries allows attackers to perform directory traversal during package decompression, enabling arbitrary file wr...
Dec 12, 2023JFinalCMS 5.0.0 contains a directory traversal vulnerability that allows remote attackers to read arbitrary files on the server. Attackers can exploit...
Dec 10, 2023CVE-2023-46307 is a directory traversal vulnerability in etcd-browser that allows attackers to read arbitrary files on the server by manipulating URL ...
Dec 7, 2023Delta Electronics InfraSuite Device Master v1.0.7 contains a path traversal vulnerability (CWE-22) that allows unauthenticated attackers to access sen...
Nov 30, 2023This vulnerability in Apache Tiles allows attackers to perform path traversal attacks when user-controlled data is passed to the DefaultLocaleResolver...
Nov 30, 2023CVE-2023-48848 is an arbitrary file read vulnerability in ureport v2.2.9 that allows remote attackers to read sensitive files on the server by manipul...
Nov 28, 2023This CVE describes a directory traversal vulnerability in TerraMaster NAS devices that allows remote attackers to access sensitive files outside the i...
Nov 17, 2023About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free