CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,172
Total CVEs
517
Critical
1,109
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
245
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 18
4 Solarwinds 17
5 Fortinet 17
6 Fedoraproject 17
7 Siemens 16
8 Samsung 16
9 Debian 16
10 Adobe 15

All Path Traversal CVEs (2,172)

CVE-2023-26691
7.2

This vulnerability allows remote attackers to execute arbitrary code on CS-Cart MultiVendor systems through directory traversal in zip file handling d...

Sep 25, 2024
CVE-2024-42501
7.2

An authenticated path traversal vulnerability in ArubaOS allows attackers to install unsigned packages on the underlying operating system. This enable...

Sep 17, 2024
CVE-2024-38878
7.2

This vulnerability allows authenticated users to exploit a path traversal flaw in the diagnostics data export API endpoint. Attackers can download arb...

Aug 2, 2024
CVE-2024-27178
7.2

This CVE-2024-27178 vulnerability in ToshibaTec products allows attackers to achieve remote code execution by exploiting a path traversal weakness to ...

Jun 14, 2024
CVE-2024-27176
7.2

This vulnerability allows attackers to achieve remote code execution by overwriting files through session ID manipulation. It primarily affects Toshib...

Jun 14, 2024
CVE-2023-41877
7.2

This CVE describes a path traversal vulnerability in GeoServer that allows administrators with access to the admin console to misconfigure log file lo...

Mar 20, 2024
CVE-2024-27081
7.2

This vulnerability in ESPHome's dashboard component allows authenticated attackers to read and write arbitrary files within the configuration director...

Feb 26, 2024
CVE-2023-6294
7.2

This vulnerability in the Popup Builder WordPress plugin allows administrators in Multisite WordPress configurations to perform Server-Side Request Fo...

Feb 12, 2024
CVE-2021-46902
7.2

This vulnerability in Meinberg LANTIME-Firmware's LTOS-Web-Interface allows authenticated admin users to bypass path validation controls, enabling una...

Feb 4, 2024
CVE-2023-50916
7.2

Kyocera Device Manager before version 3.1.1213.0 contains a path traversal vulnerability that allows attackers to force the application to authenticat...

Jan 10, 2024
CVE-2023-38126
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary code as root on Softing edgeAggregator installations by exploiting a dir...

Dec 19, 2023
CVE-2023-49788
7.2

This vulnerability in Collabora Online's Built-in CODE Server allows attackers to overwrite files outside the designated session directory by sending ...

Dec 8, 2023
CVE-2023-45880
7.2

This vulnerability allows attackers to perform directory traversal in GibbonEdu's report template builder, enabling them to create arbitrary PHP files...

Nov 14, 2023
CVE-2023-45686
7.2

This vulnerability allows authenticated attackers to write files to arbitrary locations on the filesystem via path traversal in WebDAV functionality. ...

Oct 16, 2023
CVE-2023-20890
7.2

This vulnerability allows authenticated administrative users in VMware Aria Operations for Networks to write files to arbitrary locations, potentially...

Aug 29, 2023
CVE-2023-37428
7.2

This vulnerability allows authenticated remote users to execute arbitrary commands as root on EdgeConnect SD-WAN Orchestrator systems through the web ...

Aug 22, 2023
CVE-2023-38997
7.2

A directory traversal vulnerability in OPNsense's Captive Portal templates allows attackers to upload crafted ZIP archives that can execute arbitrary ...

Aug 9, 2023
CVE-2023-36220
7.2

CVE-2023-36220 is a directory traversal vulnerability in Textpattern CMS v4.8.8 that allows authenticated remote attackers to upload malicious plugins...

Aug 7, 2023
CVE-2023-23842
7.2

CVE-2023-23842 is a directory traversal vulnerability in SolarWinds Network Configuration Manager that allows authenticated administrative users to ex...

Jul 26, 2023
CVE-2023-3172
7.2

This CVE describes a path traversal vulnerability in the Froxlor server management panel that allows attackers to access files outside the intended di...

Jun 9, 2023
CVE-2023-22773
7.2

This CVE describes an authenticated path traversal vulnerability in ArubaOS command line interface that allows authenticated attackers to delete arbit...

Mar 1, 2023
CVE-2023-0862
7.2

Authenticated users can exploit path traversal vulnerabilities in NetModule NSRW web administration interface to upload malicious files to the web roo...

Feb 16, 2023
CVE-2021-21885
7.2

This CVE describes an authenticated directory traversal vulnerability in Lantronix PremierWave 2050's Web Manager FsMove functionality. An attacker wi...

Dec 22, 2021
CVE-2021-41547
7.2

This vulnerability allows attackers to perform zip path traversal attacks through an unsafe unzipping pattern in Teamcenter Active Workspace. Successf...

Dec 14, 2021
CVE-2021-24970
7.2

This vulnerability in the All-in-One Video Gallery WordPress plugin allows attackers to include arbitrary local files on the server through an unsanit...

Dec 13, 2021
CVE-2021-34422
7.2

The Keybase Client for Windows contains a path traversal vulnerability that allows malicious users to upload specially named files to shared folders, ...

Nov 11, 2021
CVE-2021-40988
7.2

This CVE describes a remote directory traversal vulnerability in Aruba ClearPass Policy Manager that allows attackers to access files outside the inte...

Oct 15, 2021
CVE-2021-1435
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary commands as root on Cisco IOS XE devices via the web UI. Attackers can i...

Mar 24, 2021
CVE-2021-20072
7.2

This vulnerability in Racom's MIDGE Firmware allows authenticated attackers to perform directory traversal attacks, enabling arbitrary file access and...

Feb 16, 2021
CVE-2020-27871
7.2

This vulnerability allows authenticated remote attackers to bypass authentication and create arbitrary files on SolarWinds Orion Platform installation...

Feb 10, 2021
CVE-2020-3143
7.2

This directory traversal vulnerability in Cisco TelePresence video endpoint software allows authenticated attackers to read and write arbitrary files ...

Sep 23, 2020
CVE-2020-14028
7.2

CVE-2020-14028 is a path traversal vulnerability in Ozeki NG SMS Gateway's Autoreply module that allows attackers to write or overwrite arbitrary file...

Sep 22, 2020
CVE-2020-12827
7.2

CVE-2020-12827 is a path traversal vulnerability in MJML email framework versions prior to 4.6.3. Attackers can exploit the mj-include directive to re...

Jun 17, 2020
CVE-2019-15981
7.2

CVE-2019-15981 allows authenticated attackers with administrative privileges to perform directory traversal attacks through REST/SOAP API endpoints in...

Jan 6, 2020
CVE-2026-28482
7.1

OpenClaw versions before 2026.2.12 have a path traversal vulnerability where authenticated attackers can use unsanitized sessionId or sessionFile para...

Mar 5, 2026
CVE-2026-26960
7.1

CVE-2026-26960 is a path traversal vulnerability in node-tar that allows attackers to create hardlinks pointing outside the extraction directory when ...

Feb 20, 2026
CVE-2026-25640
7.1

A path traversal vulnerability in Pydantic AI's web UI allows attackers to serve malicious JavaScript by crafting URLs with unvalidated version parame...

Feb 6, 2026
CVE-2026-24049
7.1

CVE-2026-24049 is a path traversal vulnerability in Python's wheel tool (versions 0.40.0-0.46.1) that allows attackers to modify file permissions of c...

Jan 22, 2026
CVE-2026-24046
7.1

This CVE describes a symlink-based path traversal vulnerability in Backstage's Scaffolder component. Attackers with template creation/execution privil...

Jan 21, 2026
CVE-2026-22249
7.1

Docmost versions 0.21.0 through 0.23.x contain a ZipSlip vulnerability in the zip import feature that allows attackers to write arbitrary files to any...

Jan 15, 2026
CVE-2025-13661
7.1

CVE-2025-13661 is a path traversal vulnerability in Ivanti Endpoint Manager that allows authenticated remote attackers to write arbitrary files outsid...

Dec 9, 2025
CVE-2025-63365
7.1

SoftSea EPUB File Reader 1.0.0.0 contains a directory traversal vulnerability in its EPUB file processing component. Attackers can craft malicious EPU...

Dec 1, 2025
CVE-2025-3465
7.1

This path traversal vulnerability in ABB CoreSense HM and M10 devices allows attackers to access files outside the intended directory. It affects Core...

Oct 20, 2025
CVE-2025-56815
7.1

CVE-2025-56815 is a directory traversal vulnerability in Datart 1.0.0-rc.3 that allows attackers to write arbitrary files to any location on the serve...

Sep 24, 2025
CVE-2025-53080
7.1

This path traversal vulnerability in Samsung DMS allows authenticated attackers to write arbitrary files to unintended filesystem locations. Attackers...

Jul 29, 2025
CVE-2025-50819
7.1

A directory traversal vulnerability in beiyuouo arxiv-daily allows attackers to read arbitrary files on the server by manipulating the topic.yml file ...

Jul 15, 2025
CVE-2024-9597
7.1

A path traversal vulnerability in parisneo/lollms v12 allows attackers to delete arbitrary directories on the system by exploiting improper validation...

Mar 20, 2025
CVE-2025-24019
7.1

This vulnerability in YesWiki allows any authenticated user to delete arbitrary files owned by the PHP-FPM process user, potentially leading to data l...

Jan 21, 2025
CVE-2024-21799
7.1

This path traversal vulnerability in Intel Extension for Transformers allows authenticated local users to access files outside intended directories, p...

Nov 13, 2024
CVE-2024-49760
7.1

OpenRefine versions before 3.8.3 contain a path traversal vulnerability in the load-language command that allows attackers to read arbitrary JSON file...

Oct 24, 2024

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,172 CVEs classified as CWE-22, with 517 rated critical and 1,109 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free