CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,146
Total CVEs
506
Critical
1,098
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,146)

CVE-2024-33535
7.5

This vulnerability allows unauthenticated attackers to read arbitrary files from a specific directory in Zimbra Collaboration Suite. It affects Zimbra...

Aug 12, 2024
CVE-2024-41936
7.5

An unauthenticated directory traversal vulnerability in Vonets industrial wifi bridge devices allows remote attackers to read arbitrary files and bypa...

Aug 12, 2024
CVE-2024-6781
7.5

CVE-2024-6781 is a path traversal vulnerability in Calibre ebook management software that allows unauthenticated attackers to read arbitrary files fro...

Aug 6, 2024
CVE-2024-41695
7.5

This CVE describes a path traversal vulnerability in Cybonet software that allows attackers to access files outside the intended directory. Attackers ...

Jul 30, 2024
CVE-2024-41726
7.5

A path traversal vulnerability in SKYSEA Client View allows authenticated users on Windows systems to execute arbitrary executable files by manipulati...

Jul 29, 2024
CVE-2024-5882
7.5

This vulnerability in the Ultimate Classified Listings WordPress plugin allows unauthenticated attackers to access arbitrary PHP files on the server t...

Jul 29, 2024
CVE-2024-41628
7.5

This CVE describes a directory traversal vulnerability in Severalnines Cluster Control's CMON API that allows remote attackers to read arbitrary files...

Jul 26, 2024
CVE-2024-24749
7.5

This vulnerability in GeoServer allows attackers to bypass input validation and read arbitrary classpath resources with specific file extensions when ...

Jul 1, 2024
CVE-2024-6090
7.5

A path traversal vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete other users' chat histories and any .json file...

Jun 27, 2024
CVE-2024-34129
7.5

This path traversal vulnerability in Adobe Acrobat Mobile Sign for Android allows attackers to bypass directory restrictions and access or overwrite f...

Jun 13, 2024
CVE-2024-35754
7.5

This path traversal vulnerability in the Ovic Importer WordPress plugin allows attackers to download arbitrary files from the server by manipulating f...

Jun 10, 2024
CVE-2024-35745
7.5

This path traversal vulnerability in the Strategery Migrations WordPress plugin allows attackers to delete arbitrary files on the server. It affects a...

Jun 10, 2024
CVE-2024-4941
7.5

This CVE describes a local file inclusion vulnerability in gradio-app/gradio version 4.25. Attackers can exploit improper JSON parsing in the postproc...

Jun 6, 2024
CVE-2024-24869
7.5

This path traversal vulnerability in BoldGrid Total Upkeep WordPress plugin allows attackers to download arbitrary files from the server by manipulati...

May 17, 2024
CVE-2023-40297
7.5

CVE-2023-40297 is a directory traversal vulnerability in Stakater Forecastle that allows attackers to access files outside the intended web directory ...

May 15, 2024
CVE-2024-34315
7.5

CmsEasy v7.7.7.9 contains a local file inclusion vulnerability in the fckedit_action method of /admin/template_admin.php that allows attackers to read...

May 7, 2024
CVE-2023-40517
7.5

This vulnerability allows remote attackers to read arbitrary files on LG SuperSign Media Editor systems without authentication. Attackers can exploit ...

May 3, 2024
CVE-2023-40496
7.5

This vulnerability in LG Simple Editor allows remote attackers to read sensitive files on the system without authentication. Attackers can exploit a d...

May 3, 2024
CVE-2023-45385
7.5

This directory traversal vulnerability in ProQuality pqprintshippinglabels allows attackers to access files outside the intended directory via the mod...

Apr 30, 2024
CVE-2024-1593
7.5

A path traversal vulnerability in MLflow allows attackers to use ';' characters in URL parameters to access unauthorized files or directories. This af...

Apr 16, 2024
CVE-2024-1558
7.5

This path traversal vulnerability in MLflow allows attackers to read arbitrary files on the server by exploiting improper validation of the source par...

Apr 16, 2024
CVE-2024-22328
7.5

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Maximo Application Suite systems. By sending specially crafte...

Apr 6, 2024
CVE-2024-27575
7.5

CVE-2024-27575 is an absolute path traversal vulnerability in INOTEC Sicherheitstechnik WebServer CPS220/64 version 3.3.19 that allows remote attacker...

Apr 4, 2024
CVE-2021-31156
7.5

This vulnerability allows attackers to perform directory traversal attacks on Allied Telesis AT-S115 1.2.0 devices, enabling partial unauthorized acce...

Mar 28, 2024
CVE-2024-23721
7.5

CVE-2024-23721 is a directory traversal vulnerability in Draytek Vigor3910 devices that allows attackers to access sensitive system files by manipulat...

Mar 20, 2024
CVE-2023-40280
7.5

This vulnerability allows authenticated attackers to perform directory path traversal attacks in OpenClinic GA by manipulating the Page parameter in G...

Mar 19, 2024
CVE-2022-25377
7.5

This vulnerability allows unauthenticated remote attackers to read arbitrary local files on Appwrite servers via directory traversal in the ACME-chall...

Feb 22, 2024
CVE-2024-23833
7.5

OpenRefine versions up to 3.7.7 contain a JDBC attack vulnerability that allows attackers to read arbitrary files on the host filesystem. This occurs ...

Feb 12, 2024
CVE-2023-39611
7.5

This vulnerability in Software FX Chart FX 7 allows attackers to perform directory traversal attacks by sending specially crafted web requests, enabli...

Feb 2, 2024
CVE-2024-22851
7.5

A directory traversal vulnerability in LiveConfig before version 2.5.2 allows remote attackers to access sensitive files outside the intended director...

Feb 2, 2024
CVE-2024-24756
7.5

CVE-2024-24756 is a path traversal vulnerability in Crafatar that allows attackers to read files outside the intended public directory. Affected syste...

Feb 1, 2024
CVE-2024-22523
7.5

A directory traversal vulnerability in Qiyu iFair's uploadimage component allows remote attackers to access sensitive files outside the intended direc...

Jan 30, 2024
CVE-2023-48383
7.5

CVE-2023-48383 is a path traversal vulnerability in NetVision airPASS that allows unauthenticated remote attackers to bypass authentication and downlo...

Jan 15, 2024
CVE-2023-52288
7.5

CVE-2023-52288 is a directory traversal vulnerability in flaskcode versions up to 0.0.8 that allows unauthenticated attackers to read arbitrary files ...

Jan 13, 2024
CVE-2023-48166
7.5

A directory traversal vulnerability in the SOAP Server of Atos Unify OpenScape Voice V10 allows unauthenticated remote attackers to read arbitrary fil...

Jan 12, 2024
CVE-2024-22050
7.5

CVE-2024-22050 is a path traversal vulnerability in Iodine's static file service that allows unauthenticated remote attackers to read files outside th...

Jan 4, 2024
CVE-2023-37607
7.5

This directory traversal vulnerability in Automatic Systems SOC FL9600 FirstLane allows remote attackers to read sensitive files on the system by mani...

Jan 3, 2024
CVE-2023-47473
7.5

This CVE describes a directory traversal vulnerability in fuwushe.org iFair software versions 23.8_ad0 and earlier. Attackers can exploit this vulnera...

Jan 3, 2024
CVE-2023-6972
7.5

The Backup Migration plugin for WordPress has a path traversal vulnerability that allows unauthenticated attackers to delete arbitrary files via manip...

Dec 23, 2023
CVE-2023-6559
7.5

The MW WP Form WordPress plugin has a vulnerability allowing unauthenticated attackers to delete arbitrary files on the server, including critical Wor...

Dec 16, 2023
CVE-2023-50264
7.5

CVE-2023-50264 is an arbitrary file read vulnerability in Bazarr subtitle management software. Attackers can read any file on the system by manipulati...

Dec 15, 2023
CVE-2023-48373
7.5

ITPison OMICARD EDM has a path traversal vulnerability in the 'FileName' parameter that allows unauthenticated remote attackers to bypass authenticati...

Dec 15, 2023
CVE-2023-48660
7.5

CVE-2023-48660 is an arbitrary file read vulnerability in Dell vApp Manager that allows remote attackers to read arbitrary files from the target syste...

Dec 14, 2023
CVE-2023-28465
7.5

This vulnerability in HL7 FHIR Core Libraries allows attackers to perform directory traversal during package decompression, enabling arbitrary file wr...

Dec 12, 2023
CVE-2023-50449
7.5

JFinalCMS 5.0.0 contains a directory traversal vulnerability that allows remote attackers to read arbitrary files on the server. Attackers can exploit...

Dec 10, 2023
CVE-2023-46307
7.5

CVE-2023-46307 is a directory traversal vulnerability in etcd-browser that allows attackers to read arbitrary files on the server by manipulating URL ...

Dec 7, 2023
CVE-2023-47279
7.5

Delta Electronics InfraSuite Device Master v1.0.7 contains a path traversal vulnerability (CWE-22) that allows unauthenticated attackers to access sen...

Nov 30, 2023
CVE-2023-49735
7.5

This vulnerability in Apache Tiles allows attackers to perform path traversal attacks when user-controlled data is passed to the DefaultLocaleResolver...

Nov 30, 2023
CVE-2023-48848
7.5

CVE-2023-48848 is an arbitrary file read vulnerability in ureport v2.2.9 that allows remote attackers to read sensitive files on the server by manipul...

Nov 28, 2023
CVE-2023-48185
7.5

This CVE describes a directory traversal vulnerability in TerraMaster NAS devices that allows remote attackers to access sensitive files outside the i...

Nov 17, 2023

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free