CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,155)
CVE-2022-23347 is a directory traversal vulnerability in BigAnt Server that allows attackers to access files outside the intended directory. This affe...
Mar 21, 2022CVE-2022-25249 is a directory traversal vulnerability in Axeda agent and Axeda Desktop Server for Windows that allows remote unauthenticated attackers...
Mar 16, 2022This CVE describes a path traversal vulnerability in D-Link DAP-1620 devices that allows attackers to read sensitive system files like /etc/passwd and...
Mar 4, 2022This vulnerability in Qt allows attackers to load malicious system library files from unintended directories, potentially leading to arbitrary code ex...
Mar 2, 2022This CVE describes a directory traversal vulnerability in WeBankPartners wecube-platform version 3.2.1 that allows attackers to read arbitrary files o...
Feb 24, 2022CVE-2022-23612 is a path traversal vulnerability in OpenMRS that allows attackers to exfiltrate arbitrary files from the server. The vulnerability aff...
Feb 22, 2022CVE-2022-25298 is a directory traversal vulnerability in sprinfall/webcc that allows attackers to access arbitrary files on the server by manipulating...
Feb 18, 2022This vulnerability allows authenticated attackers in Ovidentia CMS 6.0 to perform path traversal attacks through the FileManager component, enabling u...
Feb 17, 2022CVE-2022-24983 is an information disclosure vulnerability in JQueryForm.com forms that allows attackers to obtain the URI of uploaded files by capturi...
Feb 16, 2022CVE-2021-35380 is a directory traversal vulnerability in Solari di Udine TermTalk Server that allows unauthenticated attackers to read arbitrary files...
Feb 15, 2022CVE-2021-43734 is a directory traversal vulnerability in kkFileView v4.0.0 that allows attackers to read arbitrary files on the server. This affects o...
Feb 15, 2022This vulnerability allows remote attackers without authentication to download arbitrary files from the server filesystem by exploiting a directory tra...
Feb 4, 2022This CVE describes a directory traversal vulnerability in iCMS content management system that allows attackers to read arbitrary files on the server. ...
Feb 4, 2022This vulnerability in convert-svg-core, convert-svg-to-png, and convert-svg-to-jpeg packages allows attackers to read arbitrary files from the server'...
Jan 21, 2022A directory traversal vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux allows authenticated attackers to r...
Jan 20, 2022CVE-2021-46104 is a directory traversal vulnerability in webp_server_go that allows attackers to read arbitrary files on the server by manipulating UR...
Jan 19, 2022CVE-2022-21371 is a local file inclusion vulnerability in Oracle WebLogic Server's web container that allows unauthenticated attackers with network ac...
Jan 19, 2022This CVE describes a directory traversal vulnerability in SphinxSearch that allows attackers to read arbitrary files on the server. When combined with...
Jan 10, 2022This vulnerability allows attackers to read arbitrary files on NavigateCMS servers by manipulating the 'id' parameter in the navigate_download.php scr...
Jan 6, 2022This vulnerability in the rust-embed crate allows directory traversal attacks in debug mode, potentially enabling attackers to read arbitrary files ou...
Dec 26, 2021This vulnerability in the True Ranker WordPress plugin allows attackers to read arbitrary files on the server, including sensitive configuration files...
Dec 14, 2021This directory traversal vulnerability in PHPGURUKUL Employee Record Management System 1.2 allows attackers to access sensitive files outside the inte...
Dec 13, 2021This vulnerability allows unauthenticated attackers to perform path traversal attacks on FortiOS and FortiProxy login pages, potentially exposing sens...
Dec 8, 2021CVE-2021-43798 is a directory traversal vulnerability in Grafana that allows attackers to read arbitrary files on the server by exploiting a flaw in t...
Dec 7, 2021This directory traversal vulnerability in Wiki.js allows attackers to read arbitrary files on Windows systems when specific storage modules are enable...
Dec 6, 2021CVE-2021-43795 is a path traversal vulnerability in Armeria microservice framework that allows attackers to bypass directory restrictions using URL-en...
Dec 2, 2021This vulnerability allows unauthenticated attackers to trick Synapse Matrix homeservers into downloading files from remote servers to arbitrary direct...
Nov 23, 2021This vulnerability allows remote attackers to read arbitrary files on Wipro Holmes Orchestrator servers via path traversal in the File Download API. A...
Nov 22, 2021CVE-2021-40745 is a path traversal vulnerability in Adobe Campaign that allows unauthenticated attackers to read arbitrary files on the server by expl...
Nov 17, 2021CVE-2021-3924 is a path traversal vulnerability in Grav CMS that allows attackers to read arbitrary files outside the intended directory. This affects...
Nov 5, 2021The Jenkins Subversion Plugin vulnerability allows attackers with agent access to read arbitrary files on the Jenkins controller file system. This aff...
Nov 4, 2021CVE-2021-33800 is a directory traversal vulnerability in Druid 1.2.3 that allows attackers to access files outside the intended directory by manipulat...
Nov 3, 2021This directory traversal vulnerability in phpok 5.1 allows attackers to access sensitive files outside the intended directory via the title parameter ...
Nov 2, 2021This path traversal vulnerability in Huawei FusionCube allows attackers to access files outside restricted directories by manipulating filenames. It a...
Oct 27, 2021Sky File v2.1.0 contains a directory traversal vulnerability in its FTP server that allows attackers to bypass directory restrictions using 'null' pat...
Oct 22, 2021This path traversal vulnerability in python-tuf allows attackers to overwrite .json files anywhere on the client system by using path traversal charac...
Oct 19, 2021CVE-2021-33726 is a path traversal vulnerability in Siemens SINEC NMS that allows authenticated attackers to download arbitrary files from the server ...
Oct 12, 2021CVE-2021-41291 is a path traversal vulnerability in ECOA BAS controllers that allows unauthenticated attackers to remotely disclose directory contents...
Sep 30, 2021CVE-2021-41381 is a directory traversal vulnerability in Payara Micro Community that allows attackers to read arbitrary files on the server filesystem...
Sep 23, 2021This vulnerability in CMS Made Simple allows unauthenticated attackers to perform path traversal attacks, potentially reading arbitrary files on the s...
Sep 17, 2021CVE-2021-33692 is a path traversal vulnerability in SAP Cloud Connector that allows attackers to upload malicious zip backup files containing director...
Sep 15, 2021Eyoucms 1.5.4 contains a directory traversal vulnerability that allows attackers to write files outside intended directories by injecting '../' sequen...
Sep 7, 2021CVE-2021-23430 is a directory traversal vulnerability in the startserver npm package that allows attackers to read arbitrary files outside the intende...
Aug 24, 2021CVE-2021-38758 is a directory traversal vulnerability in Online Catering Reservation System 1.0 that allows attackers to read arbitrary files on the s...
Aug 16, 2021This vulnerability allows remote attackers to write arbitrary files to the SAP BusinessObjects Edge 4.0 File Repository Server via a full pathname in ...
Aug 9, 2021This vulnerability allows remote attackers to write arbitrary files to the Windows temporary directory by submitting crafted paths when a Ruby web app...
Jul 30, 2021This vulnerability in elFinder.AspNet allows path traversal attacks due to improper sanitization of user-controlled file names. Attackers can potentia...
Jul 28, 2021This vulnerability in Minecraft Java Edition allows attackers to delete arbitrary JSON files via path traversal when the server is configured with onl...
Jul 20, 2021CVE-2021-34820 is a directory traversal vulnerability in the Novus HTTP Server that allows unauthenticated attackers to access arbitrary files on the ...
Jul 19, 2021This CVE describes a path traversal vulnerability in Micronaut framework versions prior to 2.5.9. Attackers can access arbitrary files on the filesyst...
Jul 16, 2021About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,155 CVEs classified as CWE-22, with 509 rated critical and 1,101 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free