CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,155
Total CVEs
509
Critical
1,101
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
243
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,155)

CVE-2022-23347
7.5

CVE-2022-23347 is a directory traversal vulnerability in BigAnt Server that allows attackers to access files outside the intended directory. This affe...

Mar 21, 2022
CVE-2022-25249
7.5

CVE-2022-25249 is a directory traversal vulnerability in Axeda agent and Axeda Desktop Server for Windows that allows remote unauthenticated attackers...

Mar 16, 2022
CVE-2021-46381
7.5

This CVE describes a path traversal vulnerability in D-Link DAP-1620 devices that allows attackers to read sensitive system files like /etc/passwd and...

Mar 4, 2022
CVE-2022-25634
7.5

This vulnerability in Qt allows attackers to load malicious system library files from unintended directories, potentially leading to arbitrary code ex...

Mar 2, 2022
CVE-2021-45746
7.5

This CVE describes a directory traversal vulnerability in WeBankPartners wecube-platform version 3.2.1 that allows attackers to read arbitrary files o...

Feb 24, 2022
CVE-2022-23612
7.5

CVE-2022-23612 is a path traversal vulnerability in OpenMRS that allows attackers to exfiltrate arbitrary files from the server. The vulnerability aff...

Feb 22, 2022
CVE-2022-25298
7.5

CVE-2022-25298 is a directory traversal vulnerability in sprinfall/webcc that allows attackers to access arbitrary files on the server by manipulating...

Feb 18, 2022
CVE-2022-22914
7.5

This vulnerability allows authenticated attackers in Ovidentia CMS 6.0 to perform path traversal attacks through the FileManager component, enabling u...

Feb 17, 2022
CVE-2022-24983
7.5

CVE-2022-24983 is an information disclosure vulnerability in JQueryForm.com forms that allows attackers to obtain the URI of uploaded files by capturi...

Feb 16, 2022
CVE-2021-35380
7.5

CVE-2021-35380 is a directory traversal vulnerability in Solari di Udine TermTalk Server that allows unauthenticated attackers to read arbitrary files...

Feb 15, 2022
CVE-2021-43734
7.5

CVE-2021-43734 is a directory traversal vulnerability in kkFileView v4.0.0 that allows attackers to read arbitrary files on the server. This affects o...

Feb 15, 2022
CVE-2021-29395
7.5

This vulnerability allows remote attackers without authentication to download arbitrary files from the server filesystem by exploiting a directory tra...

Feb 4, 2022
CVE-2021-44977
7.5

This CVE describes a directory traversal vulnerability in iCMS content management system that allows attackers to read arbitrary files on the server. ...

Feb 4, 2022
CVE-2021-23631
7.5

This vulnerability in convert-svg-core, convert-svg-to-png, and convert-svg-to-jpeg packages allows attackers to read arbitrary files from the server'...

Jan 21, 2022
CVE-2022-23119
7.5

A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux allows authenticated attackers to r...

Jan 20, 2022
CVE-2021-46104
7.5

CVE-2021-46104 is a directory traversal vulnerability in webp_server_go that allows attackers to read arbitrary files on the server by manipulating UR...

Jan 19, 2022
CVE-2022-21371
7.5

CVE-2022-21371 is a local file inclusion vulnerability in Oracle WebLogic Server's web container that allows unauthenticated attackers with network ac...

Jan 19, 2022
CVE-2020-29050
7.5

This CVE describes a directory traversal vulnerability in SphinxSearch that allows attackers to read arbitrary files on the server. When combined with...

Jan 10, 2022
CVE-2021-44351
7.5

This vulnerability allows attackers to read arbitrary files on NavigateCMS servers by manipulating the 'id' parameter in the navigate_download.php scr...

Jan 6, 2022
CVE-2021-45712
7.5

This vulnerability in the rust-embed crate allows directory traversal attacks in debug mode, potentially enabling attackers to read arbitrary files ou...

Dec 26, 2021
CVE-2021-39312
7.5

This vulnerability in the True Ranker WordPress plugin allows attackers to read arbitrary files on the server, including sensitive configuration files...

Dec 14, 2021
CVE-2021-44965
7.5

This directory traversal vulnerability in PHPGURUKUL Employee Record Management System 1.2 allows attackers to access sensitive files outside the inte...

Dec 13, 2021
CVE-2021-41024
7.5

This vulnerability allows unauthenticated attackers to perform path traversal attacks on FortiOS and FortiProxy login pages, potentially exposing sens...

Dec 8, 2021
CVE-2021-43798
7.5

CVE-2021-43798 is a directory traversal vulnerability in Grafana that allows attackers to read arbitrary files on the server by exploiting a flaw in t...

Dec 7, 2021
CVE-2021-43800
7.5

This directory traversal vulnerability in Wiki.js allows attackers to read arbitrary files on Windows systems when specific storage modules are enable...

Dec 6, 2021
CVE-2021-43795
7.5

CVE-2021-43795 is a path traversal vulnerability in Armeria microservice framework that allows attackers to bypass directory restrictions using URL-en...

Dec 2, 2021
CVE-2021-41281
7.5

This vulnerability allows unauthenticated attackers to trick Synapse Matrix homeservers into downloading files from remote servers to arbitrary direct...

Nov 23, 2021
CVE-2021-38146
7.5

This vulnerability allows remote attackers to read arbitrary files on Wipro Holmes Orchestrator servers via path traversal in the File Download API. A...

Nov 22, 2021
CVE-2021-40745
7.5

CVE-2021-40745 is a path traversal vulnerability in Adobe Campaign that allows unauthenticated attackers to read arbitrary files on the server by expl...

Nov 17, 2021
CVE-2021-3924
7.5

CVE-2021-3924 is a path traversal vulnerability in Grav CMS that allows attackers to read arbitrary files outside the intended directory. This affects...

Nov 5, 2021
CVE-2021-21698
7.5

The Jenkins Subversion Plugin vulnerability allows attackers with agent access to read arbitrary files on the Jenkins controller file system. This aff...

Nov 4, 2021
CVE-2021-33800
7.5

CVE-2021-33800 is a directory traversal vulnerability in Druid 1.2.3 that allows attackers to access files outside the intended directory by manipulat...

Nov 3, 2021
CVE-2020-18438
7.5

This directory traversal vulnerability in phpok 5.1 allows attackers to access sensitive files outside the intended directory via the title parameter ...

Nov 2, 2021
CVE-2021-37130
7.5

This path traversal vulnerability in Huawei FusionCube allows attackers to access files outside restricted directories by manipulating filenames. It a...

Oct 27, 2021
CVE-2020-23040
7.5

Sky File v2.1.0 contains a directory traversal vulnerability in its FTP server that allows attackers to bypass directory restrictions using 'null' pat...

Oct 22, 2021
CVE-2021-41131
7.5

This path traversal vulnerability in python-tuf allows attackers to overwrite .json files anywhere on the client system by using path traversal charac...

Oct 19, 2021
CVE-2021-33726
7.5

CVE-2021-33726 is a path traversal vulnerability in Siemens SINEC NMS that allows authenticated attackers to download arbitrary files from the server ...

Oct 12, 2021
CVE-2021-41291
7.5

CVE-2021-41291 is a path traversal vulnerability in ECOA BAS controllers that allows unauthenticated attackers to remotely disclose directory contents...

Sep 30, 2021
CVE-2021-41381
7.5

CVE-2021-41381 is a directory traversal vulnerability in Payara Micro Community that allows attackers to read arbitrary files on the server filesystem...

Sep 23, 2021
CVE-2019-9060
7.5

This vulnerability in CMS Made Simple allows unauthenticated attackers to perform path traversal attacks, potentially reading arbitrary files on the s...

Sep 17, 2021
CVE-2021-33692
7.5

CVE-2021-33692 is a path traversal vulnerability in SAP Cloud Connector that allows attackers to upload malicious zip backup files containing director...

Sep 15, 2021
CVE-2021-39500
7.5

Eyoucms 1.5.4 contains a directory traversal vulnerability that allows attackers to write files outside intended directories by injecting '../' sequen...

Sep 7, 2021
CVE-2021-23430
7.5

CVE-2021-23430 is a directory traversal vulnerability in the startserver npm package that allows attackers to read arbitrary files outside the intende...

Aug 24, 2021
CVE-2021-38758
7.5

CVE-2021-38758 is a directory traversal vulnerability in Online Catering Reservation System 1.0 that allows attackers to read arbitrary files on the s...

Aug 16, 2021
CVE-2015-2074
7.5

This vulnerability allows remote attackers to write arbitrary files to the SAP BusinessObjects Edge 4.0 File Repository Server via a full pathname in ...

Aug 9, 2021
CVE-2021-28966
7.5

This vulnerability allows remote attackers to write arbitrary files to the Windows temporary directory by submitting crafted paths when a Ruby web app...

Jul 30, 2021
CVE-2021-23415
7.5

This vulnerability in elFinder.AspNet allows path traversal attacks due to improper sanitization of user-controlled file names. Attackers can potentia...

Jul 28, 2021
CVE-2021-35054
7.5

This vulnerability in Minecraft Java Edition allows attackers to delete arbitrary JSON files via path traversal when the server is configured with onl...

Jul 20, 2021
CVE-2021-34820
7.5

CVE-2021-34820 is a directory traversal vulnerability in the Novus HTTP Server that allows unauthenticated attackers to access arbitrary files on the ...

Jul 19, 2021
CVE-2021-32769
7.5

This CVE describes a path traversal vulnerability in Micronaut framework versions prior to 2.5.9. Attackers can access arbitrary files on the filesyst...

Jul 16, 2021

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,155 CVEs classified as CWE-22, with 509 rated critical and 1,101 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free