CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,150
Total CVEs
507
Critical
1,101
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
240
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Fedoraproject 17
5 Solarwinds 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,150)

CVE-2021-27825
7.5

This directory traversal vulnerability in Mercury MAC1200R routers allows attackers to read arbitrary files on the device by manipulating web-static/ ...

May 29, 2023
CVE-2023-31861
7.5

CVE-2023-31861 is a directory traversal vulnerability in ZLMediaKit 4.0 that allows attackers to read arbitrary files outside the intended directory. ...

May 25, 2023
CVE-2023-30199
7.5

This vulnerability in PrestaShop's customexporter module allows attackers to bypass access controls and download sensitive files via the download.php ...

May 19, 2023
CVE-2023-26126
7.5

CVE-2023-26126 is a directory traversal vulnerability in the m.static npm package that allows attackers to read arbitrary files on the server by manip...

May 10, 2023
CVE-2023-28127
7.5

This path traversal vulnerability in Ivanti Avalanche allows attackers to access arbitrary files on the server by manipulating file path parameters. I...

May 9, 2023
CVE-2023-31181
7.5

This path traversal vulnerability in WJJ Software's InnoKB Server and InnoKB/Console allows attackers to access files outside the intended directory b...

May 8, 2023
CVE-2023-32235
7.5

CVE-2023-32235 is a directory traversal vulnerability in Ghost CMS that allows remote attackers to read arbitrary files within the active theme's fold...

May 5, 2023
CVE-2023-25289
7.5

This vulnerability allows attackers to perform directory traversal attacks on the Digital Receptie virtual reception software's embedded web server. B...

May 4, 2023
CVE-2022-48482
7.5

CVE-2022-48482 is a directory traversal vulnerability in 3CX phone management software that allows unauthenticated remote attackers to read sensitive ...

May 2, 2023
CVE-2023-31483
7.5

This vulnerability allows attackers to perform directory traversal attacks via crafted tar archives in Cauldron cbang's tar extraction functionality. ...

Apr 28, 2023
CVE-2023-25652
7.5

CVE-2023-25652 is a path traversal vulnerability in Git's `git apply --reject` command that allows attackers to write partially controlled content to ...

Apr 25, 2023
CVE-2023-30620
7.5

CVE-2023-30620 is a path traversal vulnerability in mindsdb's tarball extraction that allows attackers to write files to arbitrary locations on the se...

Apr 21, 2023
CVE-2023-26101
7.5

This path traversal vulnerability in Progress Flowmon Packet Investigator allows authenticated users to access arbitrary files on the local filesystem...

Apr 21, 2023
CVE-2023-29887
7.5

This vulnerability allows remote attackers to read arbitrary files on the server through a Local File Inclusion flaw in the test.php file of the sprea...

Apr 18, 2023
CVE-2022-34126
7.5

CVE-2022-34126 is a directory traversal vulnerability in the Activity plugin for GLPI that allows attackers to read local files on the server. This af...

Apr 16, 2023
CVE-2023-26969
7.5

CVE-2023-26969 is a directory traversal vulnerability in Atropim 1.5.26 that allows attackers to access files outside the intended directory. This aff...

Apr 14, 2023
CVE-2023-26820
7.5

CVE-2023-26820 is a path traversal vulnerability in siteproxy v1.0 that allows attackers to read arbitrary files on the server by manipulating file pa...

Apr 7, 2023
CVE-2023-1142
7.5

This vulnerability in Delta Electronics InfraSuite Device Master allows attackers to bypass authentication and retrieve sensitive system files and cre...

Mar 27, 2023
CVE-2023-25803
7.5

CVE-2023-25803 is a directory traversal vulnerability in Roxy-WI web interface that allows attackers to read arbitrary server-side files. This affects...

Mar 13, 2023
CVE-2023-26111
7.5

This vulnerability allows attackers to perform directory traversal attacks on web servers using @nubosoftware/node-static or node-static packages. By ...

Mar 6, 2023
CVE-2022-47762
7.5

CVE-2022-47762 is a path traversal vulnerability in gin-vue-admin's download module that allows attackers to read arbitrary files from the server file...

Feb 3, 2023
CVE-2022-47768
7.5

Serenissima Informatica Fast Checkin 1.0 contains a directory traversal vulnerability (CWE-22) that allows attackers to access files outside the inten...

Feb 1, 2023
CVE-2022-24992
7.5

This vulnerability in QR Code Generator v5.2.7 allows attackers to perform directory traversal through the process.php component. Attackers can read a...

Jul 25, 2022
CVE-2022-31578
7.5

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the piaoyunsoft/bt_lnmp repository. It af...

Jul 11, 2022
CVE-2022-35410
7.5

CVE-2022-35410 is a path traversal vulnerability in mat2 (metadata anonymization toolkit) that allows attackers to access sensitive files outside the ...

Jul 8, 2022
CVE-2022-34177
7.5

This vulnerability in Jenkins Pipeline: Input Step Plugin allows attackers with Pipeline configuration permissions to write arbitrary files on the Jen...

Jun 23, 2022
CVE-2022-34179
7.5

The Jenkins Embeddable Build Status Plugin before version 2.0.4 has a path traversal vulnerability that allows attackers without proper permissions to...

Jun 23, 2022
CVE-2022-33995
7.5

This path traversal vulnerability in Devolutions Remote Desktop Manager allows attackers to create or overwrite arbitrary files on the system by manip...

Jun 21, 2022
CVE-2022-31372
7.5

CVE-2022-31372 is a path traversal vulnerability in Wiris Mathtype v7.28.0 that allows attackers to access arbitrary files on the server by manipulati...

Jun 16, 2022
CVE-2022-24278
7.5

CVE-2022-24278 is a directory traversal vulnerability in convert-svg-core that allows attackers to read arbitrary files on the server by uploading spe...

Jun 10, 2022
CVE-2022-23082
7.5

CVE-2022-23082 is a path traversal vulnerability in CureKit versions v1.0.1 through v1.1.3 where the isFileOutsideDir function fails to properly sanit...

May 31, 2022
CVE-2022-30427
7.5

This vulnerability in ginadmin allows attackers to perform directory traversal attacks by manipulating path inputs without proper filtering. It affect...

May 25, 2022
CVE-2021-42183
7.5

MasaCMS 7.2.1 contains a path traversal vulnerability in the image asset API endpoint that allows attackers to read arbitrary files from the server fi...

May 5, 2022
CVE-2022-29970
7.5

This CVE describes a path traversal vulnerability in Sinatra web framework versions before 2.2.0. It allows attackers to bypass directory restrictions...

May 2, 2022
CVE-2022-29967
7.5

CVE-2022-29967 is a directory traversal vulnerability in Glewlwyd's static_compressed_inmemory_website_callback.c component that allows attackers to a...

Apr 29, 2022
CVE-2021-46420
7.5

This vulnerability allows unauthenticated attackers to perform directory traversal attacks on Franklin Fueling Systems TS-550 evo devices, potentially...

Apr 27, 2022
CVE-2021-35250
7.5

CVE-2021-35250 is a directory traversal vulnerability in SolarWinds Serv-U FTP server that allows attackers to access files outside the intended direc...

Apr 25, 2022
CVE-2022-1392
7.5

This vulnerability in the Videos sync PDF WordPress plugin allows attackers to read arbitrary files on the server through Local File Inclusion (LFI). ...

Apr 25, 2022
CVE-2022-24424
7.5

CVE-2022-24424 is a path traversal vulnerability in Dell EMC AppSync that allows remote unauthenticated attackers to read arbitrary files on the serve...

Apr 21, 2022
CVE-2022-1119
7.5

This vulnerability allows unauthenticated attackers to download arbitrary files from WordPress servers running the Simple File List plugin. Attackers ...

Apr 19, 2022
CVE-2021-43289
7.5

This vulnerability allows an attacker who has compromised a GoCD agent to upload malicious files to arbitrary directories on the GoCD server, though t...

Apr 14, 2022
CVE-2022-27279
7.5

CVE-2022-27279 is an arbitrary file read vulnerability in InHand Networks InRouter 900 Industrial 4G Router firmware. It allows attackers to read sens...

Apr 10, 2022
CVE-2021-30497
7.5

CVE-2021-30497 is an absolute path traversal vulnerability in Ivanti Avalanche (Premise) that allows unauthenticated remote attackers to read arbitrar...

Apr 6, 2022
CVE-2021-44138
7.5

CVE-2021-44138 is a directory traversal vulnerability in Caucho Resin web servers that allows attackers to read arbitrary files by using semicolons in...

Apr 4, 2022
CVE-2022-26233
7.5

CVE-2022-26233 is a directory traversal vulnerability in Barco Control Room Management Suite that allows attackers to access sensitive files and compo...

Apr 3, 2022
CVE-2022-28380
7.5

This vulnerability allows directory traversal attacks in the rc-httpd component of 9front (a Plan 9 fork) when serve-static is used. Attackers can acc...

Apr 3, 2022
CVE-2022-23793
7.5

This vulnerability allows attackers to perform path traversal attacks by uploading specially crafted tar archives to Joomla! installations. When extra...

Mar 30, 2022
CVE-2021-44124
7.5

This directory traversal vulnerability in Hiby Music Hiby OS allows attackers to access arbitrary files on the device's filesystem via the HTTP server...

Mar 28, 2022
CVE-2022-23347
7.5

CVE-2022-23347 is a directory traversal vulnerability in BigAnt Server that allows attackers to access files outside the intended directory. This affe...

Mar 21, 2022
CVE-2022-25249
7.5

CVE-2022-25249 is a directory traversal vulnerability in Axeda agent and Axeda Desktop Server for Windows that allows remote unauthenticated attackers...

Mar 16, 2022

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,150 CVEs classified as CWE-22, with 507 rated critical and 1,101 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free