CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,146
Total CVEs
506
Critical
1,098
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
236
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,146)

CVE-2023-6015
7.5

CVE-2023-6015 is a path traversal vulnerability in MLflow that allows attackers to upload arbitrary files to any location on the server's filesystem. ...

Nov 16, 2023
CVE-2023-5245
7.5

This vulnerability is a path traversal flaw in MLeap's FileUtil.extract() function that allows attackers to write arbitrary files outside the intended...

Nov 15, 2023
CVE-2023-36667
7.5

CVE-2023-36667 is a directory traversal vulnerability in Couchbase Server that allows attackers to access files outside the intended directory. This a...

Nov 8, 2023
CVE-2023-34260
7.5

This CVE describes a path traversal vulnerability in Kyocera TASKalfa 4053ci printers that allows attackers to cause denial of service via specially c...

Nov 3, 2023
CVE-2023-46863
7.5

This vulnerability allows remote attackers to read arbitrary files on Peppermint Ticket Management servers through directory traversal in file downloa...

Oct 30, 2023
CVE-2023-27170
7.5

CVE-2023-27170 is a directory traversal vulnerability in Xpand IT Write-back manager v2.3.1 that allows attackers to access files outside the intended...

Oct 26, 2023
CVE-2023-46346
7.5

This vulnerability allows unauthenticated attackers to perform path traversal attacks in the 'Product Catalog Export PRO' module for PrestaShop. Attac...

Oct 25, 2023
CVE-2023-42488
7.5

CVE-2023-42488 is a path traversal vulnerability in EisBaer Scada software that allows attackers to access files outside the intended directory. This ...

Oct 25, 2023
CVE-2023-45823
7.5

Artifact Hub versions before 1.16.0 contain a path traversal vulnerability where symbolic links in git repositories can be exploited to read arbitrary...

Oct 19, 2023
CVE-2023-38312
7.5

A directory traversal vulnerability in Valve Counter-Strike 8684 allows clients with remote control access to read arbitrary files from the game serve...

Oct 15, 2023
CVE-2023-32974
7.5

This path traversal vulnerability in QNAP operating systems allows authenticated users to read arbitrary files outside intended directories via networ...

Oct 13, 2023
CVE-2023-42796
7.5

This vulnerability allows authenticated remote attackers to perform directory traversal attacks on Siemens CP-8031 and CP-8050 MASTER MODULE devices v...

Oct 10, 2023
CVE-2023-26152
7.5

CVE-2023-26152 is a directory traversal vulnerability in the static-server npm package that allows attackers to read arbitrary files outside the inten...

Oct 3, 2023
CVE-2023-42487
7.5

CVE-2023-42487 is a path traversal vulnerability in Soundminer that allows attackers to access files outside the intended directory. This affects syst...

Sep 27, 2023
CVE-2023-42280
7.5

CVE-2023-42280 is a directory traversal vulnerability in mee-admin 1.5 that allows attackers to read arbitrary files on the server. This affects syste...

Sep 21, 2023
CVE-2023-32558
7.5

CVE-2023-32558 allows attackers to bypass Node.js's experimental permission model using the deprecated process.binding() API, enabling path traversal ...

Sep 12, 2023
CVE-2023-41578
7.5

Jeecg Boot up to version 3.5.3 contains an arbitrary file read vulnerability in the /testConnection interface. This allows attackers to read sensitive...

Sep 8, 2023
CVE-2023-39584
7.5

CVE-2023-39584 is an arbitrary file read vulnerability in Hexo static site generator that allows attackers to read sensitive files from the server fil...

Sep 8, 2023
CVE-2023-4616
7.5

CVE-2023-4616 is a path traversal vulnerability in LG LED Assistant that allows unauthenticated remote attackers to read arbitrary files on the system...

Sep 4, 2023
CVE-2023-40827
7.5

CVE-2023-40827 is a path traversal vulnerability in pf4j plugin framework versions 3.9.0 and earlier that allows remote attackers to read arbitrary fi...

Aug 28, 2023
CVE-2023-39026
7.5

This CVE describes a directory traversal vulnerability in FileMage Gateway Windows deployments that allows remote attackers to read sensitive files on...

Aug 22, 2023
CVE-2023-39141
7.5

CVE-2023-39141 is a path traversal vulnerability in webui-aria2 that allows attackers to read arbitrary files on the server. This affects systems runn...

Aug 22, 2023
CVE-2023-40274
7.5

This directory traversal vulnerability in Zola's built-in web server allows attackers to read arbitrary files outside the webroot directory. Anyone us...

Aug 14, 2023
CVE-2023-39964
7.5

CVE-2023-39964 is an arbitrary file read vulnerability in 1Panel server management panel that allows attackers to read sensitive configuration files o...

Aug 10, 2023
CVE-2023-33756
7.5

This directory traversal vulnerability in Foswiki's SpreadSheetPlugin allows attackers to access files outside the intended directory structure. It af...

Aug 8, 2023
CVE-2023-24698
7.5

This vulnerability allows attackers to perform directory traversal attacks by exploiting insufficient parameter validation in Foswiki's Sandbox compon...

Aug 8, 2023
CVE-2023-38950
7.5

An unauthenticated path traversal vulnerability in ZKTeco BioTime's iclock API allows attackers to read arbitrary files on the system by sending speci...

Aug 3, 2023
CVE-2023-0956
7.5

CVE-2023-0956 is a path traversal vulnerability in TEL-STER TelWin SCADA WebInterface that allows unauthenticated attackers to read arbitrary files on...

Aug 3, 2023
CVE-2023-33365
7.5

An unauthenticated path traversal vulnerability in Suprema BioStar 2 allows attackers to read arbitrary files from the web server. This affects BioSta...

Aug 3, 2023
CVE-2023-38956
7.5

This CVE describes a path traversal vulnerability in ZKTeco BioAccess IVS v3.3.1 that allows unauthenticated attackers to read arbitrary files on the ...

Aug 3, 2023
CVE-2023-37218
7.5

This path traversal vulnerability in Tadiran Telecom Aeonix allows attackers to access files outside the intended directory by manipulating file paths...

Jul 30, 2023
CVE-2022-31457
7.5

CVE-2022-31457 is a directory traversal vulnerability in RTX TRAP v1.0 that allows attackers to access arbitrary files on the server by sending specia...

Jul 25, 2023
CVE-2023-3813
7.5

The Jupiter X Core WordPress plugin (premium version) contains a path traversal vulnerability that allows unauthenticated attackers to download arbitr...

Jul 21, 2023
CVE-2023-30200
7.5

This vulnerability allows unauthenticated attackers to perform path traversal attacks in the 'ultimateimagetool' PrestaShop module, enabling them to d...

Jul 20, 2023
CVE-2023-37601
7.5

Office Suite Premium v10.9.1.42602 contains a local file inclusion vulnerability via the /etc/hosts component. This allows attackers to read arbitrary...

Jul 20, 2023
CVE-2023-31461
7.5

This vulnerability in SteelSeries GG gaming software allows attackers to exploit an open API listener to create and execute malicious sub-applications...

Jul 20, 2023
CVE-2023-37474
7.5

CVE-2023-37474 is a path traversal vulnerability in Copyparty file server versions before 1.8.2 that allows attackers to access files outside the web ...

Jul 14, 2023
CVE-2023-35069
7.5

This path traversal vulnerability in Bullwark security systems allows attackers to access files outside the intended directory by manipulating file pa...

Jul 13, 2023
CVE-2022-23447
7.5

This CVE describes a path traversal vulnerability in FortiExtender management interfaces that allows unauthenticated remote attackers to read arbitrar...

Jul 11, 2023
CVE-2023-36827
7.5

CVE-2023-36827 is a path traversal vulnerability in Fides privacy engineering platform that allows remote attackers to read arbitrary files on the web...

Jul 5, 2023
CVE-2023-33277
7.5

This vulnerability allows remote attackers to read sensitive files on Gira KNX/IP-Router devices via directory traversal attacks in the web interface ...

Jun 29, 2023
CVE-2023-35843
7.5

CVE-2023-35843 is a path traversal vulnerability in NocoDB that allows unauthenticated attackers to access arbitrary files on the server by manipulati...

Jun 19, 2023
CVE-2023-35852
7.5

This vulnerability allows an attacker who controls external Suricata rules to perform directory traversal attacks, potentially writing arbitrary files...

Jun 19, 2023
CVE-2023-35844
7.5

This vulnerability in Lightdash allows attackers to perform directory traversal attacks through insecure file endpoints. Attackers can access arbitrar...

Jun 19, 2023
CVE-2023-34407
7.5

CVE-2023-34407 is a directory traversal vulnerability in Harbinger Offline Player's OfflinePlayerService.exe that allows attackers to access arbitrary...

Jun 5, 2023
CVE-2023-27639
7.5

CVE-2023-27639 is a directory traversal vulnerability in the tshirtecommerce (Custom Product Designer) component for PrestaShop that allows remote att...

Jun 1, 2023
CVE-2023-29159
7.5

A directory traversal vulnerability in Starlette web framework allows unauthenticated remote attackers to access files outside the intended web root d...

Jun 1, 2023
CVE-2021-27825
7.5

This directory traversal vulnerability in Mercury MAC1200R routers allows attackers to read arbitrary files on the device by manipulating web-static/ ...

May 29, 2023
CVE-2023-31861
7.5

CVE-2023-31861 is a directory traversal vulnerability in ZLMediaKit 4.0 that allows attackers to read arbitrary files outside the intended directory. ...

May 25, 2023
CVE-2023-30199
7.5

This vulnerability in PrestaShop's customexporter module allows attackers to bypass access controls and download sensitive files via the download.php ...

May 19, 2023

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,146 CVEs classified as CWE-22, with 506 rated critical and 1,098 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free