CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,156
Total CVEs
510
Critical
1,101
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
243
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,156)

CVE-2021-32769
7.5

This CVE describes a path traversal vulnerability in Micronaut framework versions prior to 2.5.9. Attackers can access arbitrary files on the filesyst...

Jul 16, 2021
CVE-2021-33807
7.5

CVE-2021-33807 is a directory traversal vulnerability in Cartadis Gespage up to version 8.2.1, allowing attackers to access arbitrary files on the ser...

Jul 12, 2021
CVE-2021-32527
7.5

This CVE describes a path traversal vulnerability in QSAN Storage Manager that allows remote unauthenticated attackers to download arbitrary files by ...

Jul 7, 2021
CVE-2021-32516
7.5

CVE-2021-32516 is a path traversal vulnerability in QSAN Storage Manager's share_link function that allows remote attackers to download arbitrary file...

Jul 7, 2021
CVE-2021-29157
7.5

This path traversal vulnerability in Dovecot allows attackers with local filesystem access to bypass OAuth2 authentication by tricking the system into...

Jun 28, 2021
CVE-2021-29087
7.5

This path traversal vulnerability in Synology DiskStation Manager's webapi component allows remote attackers to write arbitrary files to restricted di...

Jun 23, 2021
CVE-2021-31538
7.5

CVE-2021-31538 is a path traversal vulnerability in LANCOM R&S Unified Firewall devices that allows attackers to access files outside the intended dir...

Jun 10, 2021
CVE-2020-23575
7.5

This directory traversal vulnerability in Kyocera d-COPIA253MF plus printers allows attackers to access arbitrary files on the server filesystem. Atta...

May 10, 2021
CVE-2020-10579
7.5

This vulnerability allows remote attackers to perform directory traversal attacks on Invigo Automatic Device Management (ADM) systems. By exploiting t...

Mar 25, 2021
CVE-2020-10584
7.5

This vulnerability allows remote attackers to perform directory traversal via the /admin/search_by.php script in Invigo Automatic Device Management (A...

Mar 25, 2021
CVE-2020-13924
7.5

This directory traversal vulnerability in Apache Ambari allows malicious users to construct file names that escape intended directories, enabling unau...

Mar 17, 2021
CVE-2021-26294
7.5

This vulnerability allows directory traversal attacks in AfterLogic Aurora and WebMail Pro, enabling attackers to read sensitive files like settings.x...

Mar 7, 2021
CVE-2020-9050
7.5

This CVE describes a path traversal vulnerability in the Metasys Reporting Engine (MRE) Web Services that allows remote unauthenticated attackers to a...

Feb 19, 2021
CVE-2021-20354
7.5

CVE-2021-20354 is a directory traversal vulnerability in IBM WebSphere Application Server that allows remote attackers to read arbitrary files on the ...

Feb 18, 2021
CVE-2021-22857
7.5

CVE-2021-22857 is a directory traversal vulnerability in the CGE page download function that allows attackers to download arbitrary system files. This...

Feb 17, 2021
CVE-2021-22656
7.5

CVE-2021-22656 is a directory traversal vulnerability in Advantech iView that allows attackers to read sensitive files outside the intended directory....

Feb 11, 2021
CVE-2020-20290
7.5

This directory traversal vulnerability in yccms 3.3 allows attackers to delete arbitrary files on the server by manipulating request parameters in del...

Feb 1, 2021
CVE-2021-3341
7.5

A path traversal vulnerability in DH2i's DxWebEngine component allows attackers to read arbitrary files on the host system via crafted HTTP requests. ...

Jan 29, 2021
CVE-2020-27859
7.5

CVE-2020-27859 is an unauthenticated path traversal vulnerability in NEC ESMPRO Manager that allows remote attackers to read arbitrary files on the sy...

Jan 20, 2021
CVE-2020-19360
7.5

CVE-2020-19360 is a local file inclusion vulnerability in FHEM 6.0 that allows attackers to read arbitrary files on the server through the fhem/FileLo...

Jan 20, 2021
CVE-2020-36193
7.5

This vulnerability in Archive_Tar allows attackers to write files outside the intended extraction directory via directory traversal in symbolic link h...

Jan 18, 2021
CVE-2020-13449
7.5

CVE-2020-13449 is a directory traversal vulnerability in Gotenberg's Markdown engine that allows attackers to read arbitrary files from the container ...

Jan 7, 2021
CVE-2020-36051
7.5

This directory traversal vulnerability in MiniCMS V1.10 allows remote attackers to read arbitrary files on the server by manipulating the state parame...

Jan 5, 2021
CVE-2020-35736
7.5

CVE-2020-35736 is an unauthenticated directory traversal vulnerability in GateOne web-based terminal emulator that allows attackers to download arbitr...

Dec 27, 2020
CVE-2020-35284
7.5

CVE-2020-35284 is a path traversal vulnerability in FlamingoIM that allows attackers to read arbitrary files on the server. This occurs because file-t...

Dec 26, 2020
CVE-2020-35598
7.5

This directory traversal vulnerability in ACS Advanced Comment System 1.0 allows attackers to read arbitrary files on the server by manipulating the A...

Dec 23, 2020
CVE-2020-8463
7.5

This vulnerability in Trend Micro InterScan Web Security Virtual Appliance allows attackers to bypass authorization checks for anonymous users by mani...

Dec 17, 2020
CVE-2020-5683
7.5

CVE-2020-5683 is a directory traversal vulnerability in GROWI wiki software that allows remote attackers to upload specially crafted files to arbitrar...

Dec 16, 2020
CVE-2020-7535
7.5

This path traversal vulnerability in Schneider Electric Modicon PLC web servers allows attackers to access restricted files by sending specially craft...

Dec 11, 2020
CVE-2020-29529
7.5

This vulnerability in HashiCorp go-slug allows attackers to bypass directory traversal protections when unpacking tar archives using specially crafted...

Dec 3, 2020
CVE-2020-28993
7.5

CVE-2020-28993 is a directory traversal vulnerability in ATX miniCMTS200a Broadband Gateway and Pico CMTS devices that allows unauthenticated attacker...

Dec 1, 2020
CVE-2020-28574
7.5

CVE-2020-28574 is an unauthenticated path traversal vulnerability in Trend Micro Worry-Free Business Security 10 SP1 that allows remote attackers to d...

Nov 18, 2020
CVE-2020-27553
7.5

This vulnerability allows unauthenticated attackers with network access to download any files from the /etc directory on BASETech IP cameras. It affec...

Nov 17, 2020
CVE-2020-7763
7.5

CVE-2020-7763 is a path traversal vulnerability in phantom-html-to-pdf that allows attackers to read arbitrary files on the server. This affects appli...

Nov 5, 2020
CVE-2020-7758
7.5

CVE-2020-7758 is a path traversal vulnerability in browserless-chrome that allows attackers to read arbitrary files on the server. This affects all us...

Nov 2, 2020
CVE-2020-9368
7.5

CVE-2020-9368 is a directory traversal vulnerability in the Olea Gift On Order module for PrestaShop that allows unauthenticated attackers to read arb...

Nov 2, 2020
CVE-2020-24990
7.5

CVE-2020-24990 is a directory traversal vulnerability in QSC Q-SYS Core Manager that allows remote attackers to read sensitive operating system files ...

Oct 28, 2020
CVE-2020-14864
7.5

CVE-2020-14864 is a local file inclusion vulnerability in Oracle Business Intelligence Enterprise Edition that allows unauthenticated attackers to rea...

Oct 21, 2020
CVE-2020-4776
7.5

This path traversal vulnerability in IBM Curam Social Program Management allows remote attackers to access arbitrary files on the server by manipulati...

Oct 12, 2020
CVE-2020-24219
7.5

CVE-2020-24219 is an unauthenticated path traversal vulnerability in URayTech/HiSilicon video encoders that allows attackers to read any file from the...

Oct 6, 2020
CVE-2020-25623
7.5

This CVE describes a directory traversal vulnerability in Erlang/OTP's inets httpd application. An attacker can send specially crafted HTTP requests t...

Oct 2, 2020
CVE-2020-24624
7.5

This vulnerability allows unauthenticated attackers to perform directory traversal attacks via the DownloadServlet class in HPE Pay Per Use Utility Co...

Sep 23, 2020
CVE-2020-25247
7.5

This CVE describes a directory traversal vulnerability in Hyland OnBase that allows attackers to write files to arbitrary locations on the server. Att...

Sep 11, 2020
CVE-2019-20916
7.5

This vulnerability in pip allows directory traversal attacks when installing packages from URLs. Attackers can overwrite arbitrary files on the system...

Sep 4, 2020
CVE-2020-25068
7.5

CVE-2020-25068 is a local file inclusion vulnerability in Setelsa Conacwin access control software that allows remote unauthenticated attackers to rea...

Sep 3, 2020
CVE-2020-7665
7.5

This vulnerability in the u-root uzip package allows attackers to perform path traversal attacks during zip file extraction, potentially writing files...

Sep 1, 2020
CVE-2020-7669
7.5

CVE-2020-7669 is a path traversal vulnerability in the tarutil package of u-root that allows attackers to write files outside the intended extraction ...

Sep 1, 2020
CVE-2020-15641
7.5

CVE-2020-15641 is a path traversal vulnerability in Marvell QConvergeConsole that allows unauthenticated remote attackers to read arbitrary files on t...

Aug 25, 2020
CVE-2020-24368
7.5

CVE-2020-24368 is a directory traversal vulnerability in Icinga Web2 that allows attackers to read arbitrary files accessible by the Icinga Web2 proce...

Aug 19, 2020
CVE-2020-8209
7.5

CVE-2020-8209 is an improper access control vulnerability in Citrix XenMobile Server that allows attackers to read arbitrary files on the system. This...

Aug 17, 2020

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,156 CVEs classified as CWE-22, with 510 rated critical and 1,101 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free