CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,158
Total CVEs
510
Critical
1,102
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
244
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fedoraproject 17
6 Fortinet 16
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,158)

CVE-2020-8209
7.5

CVE-2020-8209 is an improper access control vulnerability in Citrix XenMobile Server that allows attackers to read arbitrary files on the system. This...

Aug 17, 2020
CVE-2020-15592
7.5

This vulnerability allows local attackers to escalate privileges on Windows systems running vulnerable versions of SteelCentral Aternity Agent. By exp...

Jul 27, 2020
CVE-2020-7687
7.5

CVE-2020-7687 is a path traversal vulnerability in the fast-http npm package that allows attackers to read arbitrary files on the server by manipulati...

Jul 25, 2020
CVE-2020-7681
7.5

CVE-2020-7681 is a path traversal vulnerability in the marscode npm package that allows attackers to read arbitrary files on the server. This affects ...

Jul 25, 2020
CVE-2020-7683
7.5

CVE-2020-7683 is a path traversal vulnerability in rollup-plugin-server that allows attackers to read arbitrary files from the server's filesystem. Th...

Jul 25, 2020
CVE-2020-8214
7.5

A path traversal vulnerability in Survey versions below 3 allows attackers to read arbitrary files on the server by manipulating file paths. This affe...

Jul 20, 2020
CVE-2020-7684
7.5

CVE-2020-7684 is a path traversal vulnerability in rollup-plugin-serve that allows attackers to read arbitrary files on the server due to lack of path...

Jul 17, 2020
CVE-2020-15779
7.5

This path traversal vulnerability in socket.io-file allows attackers to write files outside the intended upload directory by using directory traversal...

Jul 15, 2020
CVE-2020-7667
7.5

This vulnerability allows path traversal attacks during CPIO archive extraction in the go-rpmutils library. Attackers can craft malicious archives to ...

Jun 24, 2020
CVE-2020-7664
7.5

This vulnerability allows attackers to perform path traversal attacks when extracting malicious zip archives using the github.com/unknwon/cae/zip pack...

Jun 23, 2020
CVE-2020-13158
7.5

This directory traversal vulnerability in Artica Proxy allows attackers to read arbitrary files on the server by manipulating the popup parameter in f...

Jun 22, 2020
CVE-2020-8604
7.5

CVE-2020-8604 is a path traversal vulnerability (CWE-22) in Trend Micro InterScan Web Security Virtual Appliance 6.5 that allows remote attackers to a...

May 27, 2020
CVE-2020-12116
7.5

CVE-2020-12116 is an unauthenticated arbitrary file read vulnerability in Zoho ManageEngine OpManager. Attackers can read sensitive files on the serve...

May 7, 2020
CVE-2020-8983
7.5

CVE-2020-8983 is an arbitrary file write vulnerability in Citrix ShareFile StorageZones Controller that allows remote code execution. It affects all v...

May 7, 2020
CVE-2020-7473
7.5

CVE-2020-7473 is an unauthenticated directory traversal vulnerability in Citrix ShareFile StorageZones Controller that allows attackers to access user...

May 7, 2020
CVE-2020-12649
7.5

CVE-2020-12649 is a directory traversal vulnerability in Gurbalib's help command that allows attackers to read sensitive files outside the intended di...

May 5, 2020
CVE-2020-12447
7.5

This CVE describes a Local File Inclusion vulnerability in Onkyo TX-NR585 network audio/video receivers that allows remote unauthenticated attackers o...

Apr 29, 2020
CVE-2020-6828
7.5

This vulnerability allows a malicious Android app to craft an Intent that Firefox for Android processes, potentially overwriting files in the user's p...

Apr 24, 2020
CVE-2020-12112
7.5

CVE-2020-12112 is a local file inclusion vulnerability in BigBlueButton that allows remote attackers to read sensitive files on the server. This affec...

Apr 23, 2020
CVE-2020-3177
7.5

CVE-2020-3177 is a directory traversal vulnerability in Cisco Unified Communications Manager's TAPS interface that allows unauthenticated remote attac...

Apr 15, 2020
CVE-2020-11738
7.5

This vulnerability allows attackers to perform directory traversal attacks on WordPress sites using vulnerable versions of the Snap Creek Duplicator p...

Apr 13, 2020
CVE-2020-10366
7.5

LogicalDoc before version 8.3.3 contains a directory traversal vulnerability in the /servlet.gupld endpoint. This allows attackers to read arbitrary f...

Apr 8, 2020
CVE-2020-11596
7.5

CVE-2020-11596 is a directory traversal vulnerability in CIPPlanner CIPAce 9.1 that allows unauthenticated attackers to enumerate files and directorie...

Apr 6, 2020
CVE-2020-10953
7.5

This vulnerability in GitLab EE allows attackers to perform path traversal attacks through the NPM feature, potentially accessing files outside the in...

Mar 27, 2020
CVE-2019-19297
7.5

This vulnerability allows unauthenticated remote attackers to perform path traversal attacks on SiNVR/SiVMS Video Server's streaming service, enabling...

Mar 10, 2020
CVE-2018-18894
7.5

This CVE describes a directory traversal vulnerability in the embedded web server of certain older Lexmark printers. Attackers can exploit this to acc...

Mar 10, 2020
CVE-2020-7966
7.5

CVE-2020-7966 is a directory traversal vulnerability in GitLab Enterprise Edition that allows attackers to read arbitrary files on the server. This af...

Feb 5, 2020
CVE-2020-8545
7.5

CVE-2020-8545 is a path traversal vulnerability in the Global.py component of the AIL framework version 2.8. This allows attackers to read arbitrary f...

Feb 3, 2020
CVE-2026-27800
7.4

Zed code editor versions before 0.224.4 contain a Zip Slip vulnerability in the extension archive extraction functionality. This allows malicious exte...

Feb 26, 2026
CVE-2023-31131
7.4

Greenplum Database versions before 6.22.3 have a path traversal vulnerability in tar file extraction within GPPKGs. This allows attackers to write arb...

May 15, 2023
CVE-2021-20218
7.4

This vulnerability in fabric8 kubernetes-client allows malicious pods/containers to exploit the copy command to extract files outside the intended wor...

Mar 16, 2021
CVE-2025-68902
7.3

This path traversal vulnerability in the Anona WordPress theme allows attackers to download arbitrary files from the server by manipulating file paths...

Jan 22, 2026
CVE-2025-15076
7.3

This vulnerability allows remote attackers to bypass authentication and perform path traversal attacks on Tenda CH22 routers. Attackers can access res...

Dec 25, 2025
CVE-2025-14704
7.3

This vulnerability allows remote attackers to perform path traversal attacks via the /eshell API endpoint in Shiguangwu sgwbox N3 version 2.0.25. Atta...

Dec 15, 2025
CVE-2025-59890
7.3

A path traversal vulnerability in Eaton Galileo software's file upload functionality allows attackers with local access to execute unauthorized code o...

Nov 27, 2025
CVE-2025-13262
7.3

A path traversal vulnerability in lsfusion platform allows remote attackers to manipulate file paths via the 'sid' parameter in UploadFileRequestHandl...

Nov 17, 2025
CVE-2025-10951
7.3

This path traversal vulnerability in geyang ml-logger allows attackers to access arbitrary files on the server by manipulating file paths in the log_h...

Sep 25, 2025
CVE-2025-58320
7.3

Delta Electronics DIALink has a directory traversal authentication bypass vulnerability that allows attackers to access restricted files and bypass au...

Sep 11, 2025
CVE-2025-8815
7.3

This critical vulnerability in 猫宁i Morning allows remote attackers to perform path traversal attacks via the Shiro configuration component. Attack...

Aug 10, 2025
CVE-2025-6776
7.3

This critical vulnerability in xiaoyunjie openvpn-cms-flask allows remote attackers to perform path traversal attacks via the image upload function. A...

Jun 27, 2025
CVE-2025-6772
7.3

This critical vulnerability in eosphoros-ai DB-GPT allows remote attackers to perform path traversal attacks via the import_flow function's File param...

Jun 27, 2025
CVE-2024-13181
EPSS 14.6% 7.3

CVE-2024-13181 is a path traversal vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to bypass authentication mechanisms....

Jan 14, 2025
CVE-2024-12830
7.3

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Arista NG Firewall systems via directory traversal in the cust...

Dec 20, 2024
CVE-2024-47010
7.3

CVE-2024-47010 is a path traversal vulnerability in Ivanti Avalanche that allows remote unauthenticated attackers to bypass authentication mechanisms....

Oct 8, 2024
CVE-2024-34656
7.3

A path traversal vulnerability in Samsung Notes allows local attackers to execute arbitrary code by manipulating file paths. This affects Samsung Note...

Sep 4, 2024
CVE-2024-7927
7.3

This critical vulnerability in ZZCMS 2023 allows remote attackers to perform path traversal attacks via the skin[] parameter in /admin/class.php?dowha...

Aug 19, 2024
CVE-2024-2602
7.3

This CVE describes a path traversal vulnerability (CWE-22) in Schneider Electric software that allows authenticated users to execute malicious code by...

Jul 11, 2024
CVE-2024-32465
7.3

This CVE describes a vulnerability in Git that allows attackers to bypass security protections when cloning repositories from untrusted sources. Speci...

May 14, 2024
CVE-2023-41973
7.3

This vulnerability in Zscaler Client Connector (ZSATray) allows path traversal attacks by improperly validating the 'previousInstallerName' parameter....

Mar 26, 2024
CVE-2023-24592
7.3

This path traversal vulnerability in Intel oneAPI Toolkits allows authenticated users with local access to potentially escalate privileges by manipula...

Nov 14, 2023

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,158 CVEs classified as CWE-22, with 510 rated critical and 1,102 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free