CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,959
Total CVEs
440
Critical
980
High
7.6
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
230
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 15
7 Siemens 14
8 Adobe 14
9 Fedoraproject 14
10 Synology 12

All Path Traversal CVEs (1,959)

CVE-2024-50648
9.8

yshopmall V1.0 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files, potentially leading to remote code exe...

Nov 15, 2024
CVE-2024-48510
9.8

This CVE describes a directory traversal vulnerability in DotNetZip v1.16.0 and earlier that allows remote attackers to write arbitrary files outside ...

Nov 13, 2024
CVE-2024-11150
9.8

The WordPress User Extra Fields plugin contains an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete any file on t...

Nov 13, 2024
CVE-2024-10470
9.8

This vulnerability in the WPLMS WordPress theme allows unauthenticated attackers to read and delete arbitrary files on the server due to insufficient ...

Nov 9, 2024
CVE-2024-10625
9.8

The WooCommerce Support Ticket System WordPress plugin has an arbitrary file deletion vulnerability that allows unauthenticated attackers to delete an...

Nov 9, 2024
CVE-2024-39332
9.8

CVE-2024-39332 is a critical path traversal vulnerability in Webswing 23.2.2 that allows remote attackers to modify client-side JavaScript to access a...

Oct 31, 2024
CVE-2024-41717
9.8

CVE-2024-41717 is a path traversal vulnerability in Kieback & Peter's DDC4000 series building automation controllers that allows unauthenticated attac...

Oct 22, 2024
CVE-2024-9047
9.8

The WordPress File Upload plugin has a path traversal vulnerability in wfu_file_downloader.php that allows unauthenticated attackers to read or delete...

Oct 12, 2024
CVE-2024-46446
9.8

Mecha CMS 3.0.0 has a directory traversal vulnerability that allows attackers to bypass authentication checks via manipulated cookies and URIs. This e...

Oct 7, 2024
CVE-2024-46376
9.8

Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function that allows attackers to uplo...

Sep 18, 2024
CVE-2024-7950
9.8

This vulnerability in the WP Job Portal WordPress plugin allows unauthenticated attackers to execute arbitrary PHP code on the server through local fi...

Sep 4, 2024
CVE-2024-44761
9.8

This vulnerability allows attackers to perform directory traversal attacks via specially crafted requests in EQ Enterprise Management System. Attacker...

Aug 28, 2024
CVE-2024-45256
9.8

CVE-2024-45256 is an unauthenticated arbitrary file write vulnerability in BYOB 2.0 that allows attackers to overwrite SQLite database files, leading ...

Aug 26, 2024
CVE-2024-42469
9.8

This vulnerability in openHAB's CometVisu add-on allows unauthenticated attackers to overwrite files via path traversal. If shell scripts are overwrit...

Aug 12, 2024
CVE-2024-28698
9.8

CVE-2024-28698 is a critical directory traversal vulnerability in CSLA .NET's MobileFormatter component that allows remote attackers to execute arbitr...

Jul 22, 2024
CVE-2024-6164
9.8

CVE-2024-6164 is a critical Local File Inclusion vulnerability in the Filter & Grids WordPress plugin that allows unauthenticated attackers to include...

Jul 18, 2024
CVE-2024-39171
9.8

This vulnerability in PHPVibe v11.0.46 allows attackers to bypass directory traversal protections through incomplete blacklist checks, enabling them t...

Jul 9, 2024
CVE-2024-5980
9.8

A path traversal vulnerability in PyTorch Lightning's /v1/runs API endpoint allows attackers to write arbitrary files anywhere on the local filesystem...

Jun 27, 2024
CVE-2024-4885
9.8

An unauthenticated remote code execution vulnerability in Progress WhatsUp Gold allows attackers to execute arbitrary commands with IIS application po...

Jun 25, 2024
CVE-2024-34313
9.8

This vulnerability in VPL Jail System allows attackers to perform directory traversal attacks by sending specially crafted requests to a public endpoi...

Jun 24, 2024
CVE-2024-33879
9.8

This vulnerability in Virto Bulk File Download for SharePoint allows attackers to download and delete arbitrary files on the server via path traversal...

Jun 24, 2024
CVE-2023-45197
9.8

This vulnerability allows attackers to upload malicious files to the root directory of Adminer/AdminerEvo installations using a directory traversal te...

Jun 21, 2024
CVE-2024-27174
9.8

This CVE describes a path traversal vulnerability (CWE-22) in ToshibaTec products that allows remote command execution when combined with other vulner...

Jun 14, 2024
CVE-2024-27145
9.8

This CVE describes a path traversal vulnerability (CWE-22) in Toshiba printers' admin web interface that allows file uploads to overwrite arbitrary fi...

Jun 14, 2024
CVE-2024-3322
9.8

This path traversal vulnerability in the lollms-webui's codeguard personality allows attackers to read and overwrite arbitrary files on the system by ...

Jun 6, 2024
CVE-2024-34832
9.8

This CVE describes a directory traversal vulnerability in CubeCart that allows attackers to upload malicious files to arbitrary locations on the serve...

Jun 6, 2024
CVE-2024-27776
9.8

CVE-2024-27776 is a critical path traversal vulnerability in MileSight DeviceHub that allows unauthenticated attackers to execute arbitrary code on af...

Jun 2, 2024
CVE-2024-32113
9.8

This path traversal vulnerability in Apache OFBiz allows attackers to access files outside the intended directory by manipulating file paths. It affec...

May 8, 2024
CVE-2023-40497
9.8

This is a critical directory traversal vulnerability in LG Simple Editor that allows unauthenticated remote attackers to write arbitrary files and exe...

May 3, 2024
CVE-2024-33350
9.8

A directory traversal vulnerability in TaoCMS v3.0.2 allows remote attackers to write arbitrary files via the include/model/file.php component. This c...

Apr 29, 2024
CVE-2024-31818
9.8

A directory traversal vulnerability in DerbyNet v9.0 allows remote attackers to execute arbitrary code via the 'page' parameter in kiosk.php. This aff...

Apr 12, 2024
CVE-2024-31848
9.8

This path traversal vulnerability in CData API Server's Java version allows unauthenticated remote attackers to bypass security controls and gain admi...

Apr 5, 2024
CVE-2024-28222
9.8

This critical vulnerability allows unauthenticated attackers to upload and execute arbitrary files on Veritas NetBackup systems by exploiting improper...

Mar 7, 2024
CVE-2024-27764
9.8

A privilege escalation vulnerability in Jeewms versions 3.7 and earlier allows remote attackers to bypass authentication controls via the AuthIntercep...

Mar 5, 2024
CVE-2024-25830
9.8

F-logic DataCube3 v1.0 has an improper directory access restriction vulnerability that allows unauthenticated remote attackers to access configuration...

Feb 29, 2024
CVE-2023-40266
9.8

This vulnerability allows attackers to perform path traversal attacks on Atos Unify OpenScape Xpressions WebAssistant V7 systems. Attackers can potent...

Feb 8, 2024
CVE-2024-24398
9.8

This CVE describes a critical directory traversal vulnerability in Stimulsoft Dashboard.JS that allows remote attackers to execute arbitrary code by s...

Feb 6, 2024
CVE-2023-7077
9.8

This vulnerability allows remote attackers to execute arbitrary code on Sharp NEC displays by sending specially crafted HTTP requests with unintended ...

Feb 5, 2024
CVE-2024-24482
9.8

CVE-2024-24482 is a path traversal vulnerability in Apktool on Windows that allows attackers to write files outside intended directories using '../' s...

Feb 2, 2024
CVE-2024-23827
9.8

CVE-2024-23827 is a critical path traversal vulnerability in Nginx-UI's Import Certificate feature that allows attackers to write arbitrary files to t...

Jan 29, 2024
CVE-2024-23897
9.8

This vulnerability in Jenkins allows unauthenticated attackers to read arbitrary files on the Jenkins controller file system by exploiting a CLI comma...

Jan 24, 2024
CVE-2023-6623
9.8

This vulnerability in the Essential Blocks WordPress plugin allows unauthenticated attackers to overwrite local variables when rendering templates via...

Jan 15, 2024
CVE-2023-49569
9.8

A path traversal vulnerability in go-git versions before v5.11 allows attackers to create and modify files anywhere on the filesystem when using Chroo...

Jan 12, 2024
CVE-2023-6190
9.8

This path traversal vulnerability allows attackers to access files outside the intended directory by manipulating file paths. It affects İzmir Katip ...

Dec 27, 2023
CVE-2023-5991
9.8

This vulnerability in the Hotel Booking Lite WordPress plugin allows unauthenticated attackers to download and delete arbitrary files on the server du...

Dec 26, 2023
CVE-2023-6026
9.8

A path traversal vulnerability in elijaa/phpmemcachedadmin version 1.3.0 allows attackers to delete arbitrary files on the server by manipulating user...

Nov 30, 2023
CVE-2023-42000
9.8

Arcserve UDP versions before 9.2 contain a path traversal vulnerability in the FileHandlingServlet that allows unauthenticated remote attackers to upl...

Nov 27, 2023
CVE-2023-39332
9.8

This vulnerability allows path traversal attacks in Node.js when using non-Buffer Uint8Array objects with fs module functions. Attackers can potential...

Oct 18, 2023
CVE-2023-44171
9.8

SeaCMS V12.9 contains an arbitrary file write vulnerability in admin_smtp.php that allows attackers to write malicious files to the server. This affec...

Sep 27, 2023
CVE-2023-44169
9.8

SeaCMS V12.9 contains an arbitrary file write vulnerability in admin_notify.php that allows attackers to write malicious files to the server. This aff...

Sep 27, 2023

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,959 CVEs classified as CWE-22, with 440 rated critical and 980 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free