CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,156)
This CVE describes a path traversal vulnerability in Micronaut framework versions prior to 2.5.9. Attackers can access arbitrary files on the filesyst...
Jul 16, 2021CVE-2021-33807 is a directory traversal vulnerability in Cartadis Gespage up to version 8.2.1, allowing attackers to access arbitrary files on the ser...
Jul 12, 2021This CVE describes a path traversal vulnerability in QSAN Storage Manager that allows remote unauthenticated attackers to download arbitrary files by ...
Jul 7, 2021CVE-2021-32516 is a path traversal vulnerability in QSAN Storage Manager's share_link function that allows remote attackers to download arbitrary file...
Jul 7, 2021This path traversal vulnerability in Dovecot allows attackers with local filesystem access to bypass OAuth2 authentication by tricking the system into...
Jun 28, 2021This path traversal vulnerability in Synology DiskStation Manager's webapi component allows remote attackers to write arbitrary files to restricted di...
Jun 23, 2021CVE-2021-31538 is a path traversal vulnerability in LANCOM R&S Unified Firewall devices that allows attackers to access files outside the intended dir...
Jun 10, 2021This directory traversal vulnerability in Kyocera d-COPIA253MF plus printers allows attackers to access arbitrary files on the server filesystem. Atta...
May 10, 2021This vulnerability allows remote attackers to perform directory traversal attacks on Invigo Automatic Device Management (ADM) systems. By exploiting t...
Mar 25, 2021This vulnerability allows remote attackers to perform directory traversal via the /admin/search_by.php script in Invigo Automatic Device Management (A...
Mar 25, 2021This directory traversal vulnerability in Apache Ambari allows malicious users to construct file names that escape intended directories, enabling unau...
Mar 17, 2021This vulnerability allows directory traversal attacks in AfterLogic Aurora and WebMail Pro, enabling attackers to read sensitive files like settings.x...
Mar 7, 2021This CVE describes a path traversal vulnerability in the Metasys Reporting Engine (MRE) Web Services that allows remote unauthenticated attackers to a...
Feb 19, 2021CVE-2021-20354 is a directory traversal vulnerability in IBM WebSphere Application Server that allows remote attackers to read arbitrary files on the ...
Feb 18, 2021CVE-2021-22857 is a directory traversal vulnerability in the CGE page download function that allows attackers to download arbitrary system files. This...
Feb 17, 2021CVE-2021-22656 is a directory traversal vulnerability in Advantech iView that allows attackers to read sensitive files outside the intended directory....
Feb 11, 2021This directory traversal vulnerability in yccms 3.3 allows attackers to delete arbitrary files on the server by manipulating request parameters in del...
Feb 1, 2021A path traversal vulnerability in DH2i's DxWebEngine component allows attackers to read arbitrary files on the host system via crafted HTTP requests. ...
Jan 29, 2021CVE-2020-27859 is an unauthenticated path traversal vulnerability in NEC ESMPRO Manager that allows remote attackers to read arbitrary files on the sy...
Jan 20, 2021CVE-2020-19360 is a local file inclusion vulnerability in FHEM 6.0 that allows attackers to read arbitrary files on the server through the fhem/FileLo...
Jan 20, 2021This vulnerability in Archive_Tar allows attackers to write files outside the intended extraction directory via directory traversal in symbolic link h...
Jan 18, 2021CVE-2020-13449 is a directory traversal vulnerability in Gotenberg's Markdown engine that allows attackers to read arbitrary files from the container ...
Jan 7, 2021This directory traversal vulnerability in MiniCMS V1.10 allows remote attackers to read arbitrary files on the server by manipulating the state parame...
Jan 5, 2021CVE-2020-35736 is an unauthenticated directory traversal vulnerability in GateOne web-based terminal emulator that allows attackers to download arbitr...
Dec 27, 2020CVE-2020-35284 is a path traversal vulnerability in FlamingoIM that allows attackers to read arbitrary files on the server. This occurs because file-t...
Dec 26, 2020This directory traversal vulnerability in ACS Advanced Comment System 1.0 allows attackers to read arbitrary files on the server by manipulating the A...
Dec 23, 2020This vulnerability in Trend Micro InterScan Web Security Virtual Appliance allows attackers to bypass authorization checks for anonymous users by mani...
Dec 17, 2020CVE-2020-5683 is a directory traversal vulnerability in GROWI wiki software that allows remote attackers to upload specially crafted files to arbitrar...
Dec 16, 2020This path traversal vulnerability in Schneider Electric Modicon PLC web servers allows attackers to access restricted files by sending specially craft...
Dec 11, 2020This vulnerability in HashiCorp go-slug allows attackers to bypass directory traversal protections when unpacking tar archives using specially crafted...
Dec 3, 2020CVE-2020-28993 is a directory traversal vulnerability in ATX miniCMTS200a Broadband Gateway and Pico CMTS devices that allows unauthenticated attacker...
Dec 1, 2020CVE-2020-28574 is an unauthenticated path traversal vulnerability in Trend Micro Worry-Free Business Security 10 SP1 that allows remote attackers to d...
Nov 18, 2020This vulnerability allows unauthenticated attackers with network access to download any files from the /etc directory on BASETech IP cameras. It affec...
Nov 17, 2020CVE-2020-7763 is a path traversal vulnerability in phantom-html-to-pdf that allows attackers to read arbitrary files on the server. This affects appli...
Nov 5, 2020CVE-2020-7758 is a path traversal vulnerability in browserless-chrome that allows attackers to read arbitrary files on the server. This affects all us...
Nov 2, 2020CVE-2020-9368 is a directory traversal vulnerability in the Olea Gift On Order module for PrestaShop that allows unauthenticated attackers to read arb...
Nov 2, 2020CVE-2020-24990 is a directory traversal vulnerability in QSC Q-SYS Core Manager that allows remote attackers to read sensitive operating system files ...
Oct 28, 2020CVE-2020-14864 is a local file inclusion vulnerability in Oracle Business Intelligence Enterprise Edition that allows unauthenticated attackers to rea...
Oct 21, 2020This path traversal vulnerability in IBM Curam Social Program Management allows remote attackers to access arbitrary files on the server by manipulati...
Oct 12, 2020CVE-2020-24219 is an unauthenticated path traversal vulnerability in URayTech/HiSilicon video encoders that allows attackers to read any file from the...
Oct 6, 2020This CVE describes a directory traversal vulnerability in Erlang/OTP's inets httpd application. An attacker can send specially crafted HTTP requests t...
Oct 2, 2020This vulnerability allows unauthenticated attackers to perform directory traversal attacks via the DownloadServlet class in HPE Pay Per Use Utility Co...
Sep 23, 2020This CVE describes a directory traversal vulnerability in Hyland OnBase that allows attackers to write files to arbitrary locations on the server. Att...
Sep 11, 2020This vulnerability in pip allows directory traversal attacks when installing packages from URLs. Attackers can overwrite arbitrary files on the system...
Sep 4, 2020CVE-2020-25068 is a local file inclusion vulnerability in Setelsa Conacwin access control software that allows remote unauthenticated attackers to rea...
Sep 3, 2020This vulnerability in the u-root uzip package allows attackers to perform path traversal attacks during zip file extraction, potentially writing files...
Sep 1, 2020CVE-2020-7669 is a path traversal vulnerability in the tarutil package of u-root that allows attackers to write files outside the intended extraction ...
Sep 1, 2020CVE-2020-15641 is a path traversal vulnerability in Marvell QConvergeConsole that allows unauthenticated remote attackers to read arbitrary files on t...
Aug 25, 2020CVE-2020-24368 is a directory traversal vulnerability in Icinga Web2 that allows attackers to read arbitrary files accessible by the Icinga Web2 proce...
Aug 19, 2020CVE-2020-8209 is an improper access control vulnerability in Citrix XenMobile Server that allows attackers to read arbitrary files on the system. This...
Aug 17, 2020About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,156 CVEs classified as CWE-22, with 510 rated critical and 1,101 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free