CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,967
Total CVEs
440
Critical
988
High
7.6
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Adobe 15
8 Siemens 14
9 Fedoraproject 14
10 Synology 12

All Path Traversal CVEs (1,967)

CVE-2023-43216
9.8

SeaCMS V12.9 contains an arbitrary file write vulnerability in admin_ip.php that allows attackers to write malicious files to the server. This affects...

Sep 27, 2023
CVE-2022-28357
9.8

CVE-2022-28357 is a directory traversal vulnerability in NATS nats-server that allows management accounts to access arbitrary files outside the intend...

Sep 19, 2023
CVE-2023-4614
9.8

This critical vulnerability in LG LED Assistant allows unauthenticated remote attackers to execute arbitrary code by exploiting improper path validati...

Sep 4, 2023
CVE-2023-4613
9.8

CVE-2023-4613 is a critical path traversal vulnerability in LG LED Assistant that allows unauthenticated remote attackers to execute arbitrary code. A...

Sep 4, 2023
CVE-2023-39699
9.8

IceWarp Mail Server v10.4.5 contains a local file inclusion vulnerability in the /calendar/minimizer/index.php component that allows attackers to read...

Aug 25, 2023
CVE-2023-26469
9.8

CVE-2023-26469 is a critical path traversal vulnerability in Jorani 1.0.0 that allows attackers to access arbitrary files on the server and execute re...

Aug 17, 2023
CVE-2020-26037
9.8

This CVE describes a directory traversal vulnerability in Even Balance Punkbuster anti-cheat software that allows remote attackers to execute arbitrar...

Aug 16, 2023
CVE-2023-39143
9.8

CVE-2023-39143 is a path traversal vulnerability in PaperCut NG/MF on Windows that allows attackers to upload, read, or delete arbitrary files. When e...

Aug 4, 2023
CVE-2023-38951
9.8

This vulnerability in ZKTeco BioTime allows authenticated attackers to perform path traversal attacks via crafted requests to /base/sftpsetting/ endpo...

Aug 3, 2023
CVE-2022-46898
9.8

This vulnerability allows attackers to perform path traversal attacks via the 'restore SQL data' filename in Vocera Report Server and Voice Server. By...

Jul 25, 2023
CVE-2023-34478
9.8

This CVE describes an authentication bypass vulnerability in Apache Shiro that allows attackers to bypass security controls through path traversal tec...

Jul 24, 2023
CVE-2023-26563
9.8

CVE-2023-26563 is a critical directory traversal vulnerability in Syncfusion EJ2 Node File Provider that allows unauthenticated attackers to read, del...

Jul 12, 2023
CVE-2023-34598
9.8

CVE-2023-34598 is a Local File Inclusion vulnerability in Gibbon v25.0.0 that allows attackers to read sensitive files from the server's installation ...

Jun 29, 2023
CVE-2020-19902
9.8

CVE-2020-19902 is a critical directory traversal vulnerability in Cryptoprof WCMS v0.3.2 that allows remote attackers to execute arbitrary code via th...

Jun 27, 2023
CVE-2023-30945
9.8

This vulnerability allows unauthenticated attackers to read, write, or delete arbitrary files on affected systems due to insufficient filename validat...

Jun 26, 2023
CVE-2023-32557
9.8

This critical vulnerability allows unauthenticated attackers to upload arbitrary files to Trend Micro Apex One management servers via path traversal, ...

Jun 26, 2023
CVE-2023-34939
9.8

CVE-2023-34939 is a critical remote code execution vulnerability in ONLYOFFICE Community Server's UploadProgress.ashx component that allows attackers ...

Jun 22, 2023
CVE-2023-34880
9.8

CVE-2023-34880 is a critical path traversal vulnerability in cmseasy CMS that allows attackers to execute arbitrary code via local file inclusion. Thi...

Jun 15, 2023
CVE-2023-34865
9.8

A directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files to arbitrary locations on the server via the rename feature. This af...

Jun 14, 2023
CVE-2023-34409
9.8

This vulnerability allows unauthenticated remote attackers to bypass authentication in Percona Monitoring and Management (PMM) servers by exploiting p...

Jun 6, 2023
CVE-2023-29736
9.8

Keyboard Themes 1.275.1.164 for Android contains a path traversal vulnerability that allows unauthorized apps to write arbitrary files to its internal...

Jun 1, 2023
CVE-2022-24629
9.8

This vulnerability allows remote attackers to execute arbitrary code on AudioCodes Device Manager Express servers via directory traversal in file uplo...

May 29, 2023
CVE-2023-28408
9.8

A directory traversal vulnerability in MW WP Form plugin versions 4.4.2 and earlier allows unauthenticated remote attackers to access files outside th...

May 23, 2023
CVE-2023-28413
9.8

A directory traversal vulnerability in Snow Monkey Forms allows unauthenticated attackers to access files outside the intended directory. This affects...

May 23, 2023
CVE-2023-27507
9.8

MicroEngine Mailform versions 1.1.0 to 1.1.8 contain a path traversal vulnerability in the file upload function. When the server save option is enable...

May 23, 2023
CVE-2020-20012
9.8

WebPlus Pro v1.4.7.8.4-01 has an incorrect access control vulnerability (CWE-22) that allows attackers to bypass authentication or authorization mecha...

May 23, 2023
CVE-2022-47757
9.8

A path traversal vulnerability in imo.im allows attackers to write malicious shared libraries to the application's data directory via unsanitized deep...

May 4, 2023
CVE-2022-47027
9.8

This vulnerability in Timmystudios Fast Typing Keyboard allows unauthorized apps to overwrite arbitrary files in the keyboard's internal storage via a...

Apr 14, 2023
CVE-2023-27648
9.8

This CVE describes a directory traversal vulnerability in T-ME Studios' 'Change Color of Keypad' Android app that allows remote attackers to execute a...

Apr 14, 2023
CVE-2023-1478
9.8

The Hummingbird WordPress plugin before version 3.4.2 has a path traversal vulnerability in its page cache module. Attackers can write arbitrary files...

Apr 10, 2023
CVE-2023-29478
9.8

BiblioCraft mod for Minecraft has a path traversal vulnerability that allows attackers to write files to arbitrary locations on the filesystem. This c...

Apr 7, 2023
CVE-2020-19279
9.8

CVE-2020-19279 is a directory traversal vulnerability in B3log Wide that allows attackers to access arbitrary files on the server via symbolic link ma...

Apr 4, 2023
CVE-2022-36981
9.8

This is a critical path traversal vulnerability in Ivanti Avalanche that allows authenticated attackers to bypass authentication mechanisms and execut...

Mar 29, 2023
CVE-2023-26802
9.8

This critical vulnerability in DCN DCBI-Netlog-LAB allows unauthenticated attackers to bypass authentication and execute arbitrary commands on affecte...

Mar 26, 2023
CVE-2023-27855
9.8

CVE-2023-27855 is a critical path traversal vulnerability in Rockwell Automation's ThinManager ThinServer that allows unauthenticated remote attackers...

Mar 22, 2023
CVE-2023-28371
9.8

CVE-2023-28371 is a path traversal vulnerability in Stellarium that allows attackers to write files to unintended locations using absolute paths or di...

Mar 15, 2023
CVE-2021-33353
9.8

This CVE describes a directory traversal vulnerability in Wyomind Help Desk Magento 2 extension that allows attackers to execute arbitrary code via fi...

Mar 8, 2023
CVE-2023-22336
9.8

This is a path traversal vulnerability in SS1 and Rakuraku PC Cloud Agent software that allows attackers to upload files to arbitrary directories. Whe...

Mar 6, 2023
CVE-2023-0947
9.8

This CVE describes a path traversal vulnerability in FlatPress blogging software that allows attackers to read arbitrary files on the server. It affec...

Feb 22, 2023
CVE-2021-36471
9.8

This CVE describes a directory traversal vulnerability in AdminLTE 3.1.0 that allows remote attackers to access sensitive admin pages via specific URI...

Feb 7, 2023
CVE-2022-45969
9.8

CVE-2022-45969 is a directory traversal vulnerability in Alist v3.4.0 that allows attackers to access files outside the intended directory. This affec...

Dec 15, 2022
CVE-2022-32409
9.8

This CVE describes a Local File Inclusion (LFI) vulnerability in Portal do Software Publico Brasileiro i3geo version 7.0.5 that allows attackers to ex...

Jul 14, 2022
CVE-2022-31570
9.8

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the adriankoczuruek/ceneo-web-scrapper re...

Jul 11, 2022
CVE-2022-25046
9.8

CVE-2022-25046 is a critical path traversal vulnerability in CentOS Web Panel (CWP) that allows unauthenticated attackers to execute arbitrary code on...

Jul 7, 2022
CVE-2022-28945
9.8

CVE-2022-28945 is a critical directory traversal vulnerability in Webbank WeCube v3.2.2 that allows attackers to write arbitrary files to the server f...

Jun 2, 2022
CVE-2022-1664
9.8

This vulnerability in dpkg allows directory traversal when extracting specially crafted source packages, enabling attackers to write arbitrary files o...

May 26, 2022
CVE-2022-29596
9.8

CVE-2022-29596 is an authentication bypass vulnerability in MicroStrategy Enterprise Manager 2022 that allows attackers to bypass login controls throu...

May 11, 2022
CVE-2022-29081
9.8

This vulnerability allows attackers to bypass access controls on specific REST API endpoints in Zoho ManageEngine products by using '../RestAPI' in UR...

Apr 28, 2022
CVE-2022-1390
9.8

The Admin Word Count Column WordPress plugin through version 2.2 contains a path traversal vulnerability in the readfile() function that allows unauth...

Apr 25, 2022
CVE-2022-29464
9.8

CVE-2022-29464 is a critical unrestricted file upload vulnerability in multiple WSO2 products that allows attackers to upload malicious files to web-a...

Apr 18, 2022

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,967 CVEs classified as CWE-22, with 440 rated critical and 988 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free