CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,221
Total CVEs
535
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
249
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Ivanti 19
4 Fedoraproject 19
5 Debian 18
6 Solarwinds 17
7 Fortinet 17
8 Adobe 17
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,221)

CVE-2025-0703
4.3

This CVE describes a path traversal vulnerability in JoeyBling bootplus that allows attackers to access files outside the intended directory by manipu...

Jan 24, 2025
CVE-2025-0461
4.3

This CVE describes a path traversal vulnerability in Shanghai Lingdang Information Technology's Lingdang CRM software. Attackers can manipulate the 'p...

Jan 14, 2025
CVE-2024-12429
4.3

An authenticated attacker can exploit this vulnerability in AC500 V3 products to read system-wide files and configurations. This affects all AC500 V3 ...

Jan 7, 2025
CVE-2024-12793
4.3

This CVE-2024-12793 is a path traversal vulnerability in PbootCMS that allows attackers to access files outside the intended directory by manipulating...

Dec 19, 2024
CVE-2024-12362
4.3

This CVE describes a path traversal vulnerability in InvoicePlane's invoices.php file that allows attackers to access arbitrary files on the server by...

Dec 16, 2024
CVE-2024-49421
4.3

This CVE describes a path traversal vulnerability in Samsung's Quick Share Agent on Android devices. It allows adjacent attackers (on the same network...

Dec 3, 2024
CVE-2024-49411
4.3

This path traversal vulnerability in Samsung's ThemeCenter allows physical attackers with device access to copy APK files to arbitrary locations using...

Dec 3, 2024
CVE-2024-50559
4.3

This vulnerability affects multiple Siemens industrial network devices where improper filename validation for certificates allows authenticated remote...

Nov 12, 2024
CVE-2024-48213
4.3

RockOA v2.6.5 contains a directory traversal vulnerability in the beifenAction.php file that allows attackers to read arbitrary files on the server by...

Oct 23, 2024
CVE-2024-8876
4.3

This path traversal vulnerability in TpMeCMS allows attackers to access files outside the intended directory by manipulating the 'lang' parameter in t...

Sep 15, 2024
CVE-2024-8707
4.3

This vulnerability allows remote attackers to perform path traversal attacks in Yunke Online School System versions up to 3.0.6. By manipulating the '...

Sep 12, 2024
CVE-2024-8410
4.3

This vulnerability allows remote attackers to perform path traversal attacks via the 'sitio' parameter in the /abcd/opac/php/otros_sitios.php file in ...

Sep 4, 2024
CVE-2024-8165
4.3

This CVE describes a path traversal vulnerability in BeikeShop's exportZip function that allows attackers to access files outside the intended directo...

Aug 26, 2024
CVE-2024-5852
4.3

The WordPress File Upload plugin contains a directory traversal vulnerability that allows authenticated attackers with Contributor-level access or hig...

Jul 16, 2024
CVE-2024-39741
4.3

This vulnerability allows remote attackers to perform directory traversal attacks on IBM Datacap Navigator systems. By sending specially crafted URLs ...

Jul 15, 2024
CVE-2024-39330
4.3

This vulnerability allows directory traversal attacks in Django applications that use custom Storage subclasses. Attackers can potentially read or wri...

Jul 10, 2024
CVE-2024-3107
4.3

The Spectra WordPress plugin (formerly Ultimate Addons for Gutenberg) has a path traversal vulnerability that allows authenticated users with contribu...

May 2, 2024
CVE-2025-22238
4.2

This CVE describes a directory traversal vulnerability in SaltStack's master cache creation that allows attackers to write or overwrite files outside ...

Jun 13, 2025
CVE-2026-29190
4.1

CVE-2026-29190 is a path traversal vulnerability in Karapace's backup reader that allows arbitrary file read when processing malicious backup files. T...

Mar 7, 2026
CVE-2025-53905
4.1

A path traversal vulnerability in Vim's tar.vim plugin allows specially crafted tar archives to overwrite arbitrary files when opened. This affects Vi...

Jul 15, 2025
CVE-2025-21015
4.0

A path traversal vulnerability in Samsung's Document scanner allows local attackers to delete arbitrary files with the application's elevated privileg...

Aug 6, 2025
CVE-2025-43250
4.0

A path validation vulnerability in macOS allows applications to escape their sandbox restrictions. This affects macOS Ventura, Sonoma, and Sequoia ver...

Jul 30, 2025
CVE-2025-43206
4.0

A path validation vulnerability in macOS allows applications to bypass directory restrictions and access protected user data. This affects macOS Ventu...

Jul 30, 2025
CVE-2024-36795
4.0

This vulnerability involves insecure permissions in Netgear WNR614 JNR1010V2 routers, allowing attackers to access URLs and directories embedded withi...

Jun 6, 2024
CVE-2025-15589
3.8

This CVE describes a path traversal vulnerability in MuYuCMS 2.7's Template Management Page. Attackers can remotely exploit the delete_dir_file functi...

Feb 24, 2026
CVE-2025-15187
3.8

This vulnerability in GreenCMS allows remote attackers to perform path traversal attacks by manipulating sqlFiles or zipFiles parameters in the File H...

Dec 29, 2025
CVE-2025-54559
3.7

This path traversal vulnerability in Desktop Alert PingAlert allows attackers to load arbitrary external content by manipulating file paths. It affect...

Nov 14, 2025
CVE-2025-15245
3.5

This vulnerability allows local network attackers to perform path traversal attacks via the firmware update service in D-Link DCS-850L cameras. By man...

Dec 30, 2025
CVE-2025-64757
3.5

A vulnerability in Astro framework's development server allows attackers to read arbitrary local image files through the image optimization endpoint. ...

Nov 19, 2025
CVE-2026-1588
2.7

This CVE describes a path traversal vulnerability in jshERP up to version 3.6 that allows remote attackers to manipulate file paths during plugin inst...

Jan 29, 2026
CVE-2025-13879
2.7

A directory traversal vulnerability in SOLIDserver IPAM v8.2.3 allows authenticated administrators to list directories outside their authorized scope ...

Dec 2, 2025
CVE-2025-12923
2.7

This vulnerability in ChestnutCMS allows attackers to perform path traversal attacks via the resourceDownload function, enabling unauthorized file rea...

Nov 10, 2025
CVE-2026-1532
2.4

This CVE describes a path traversal vulnerability in D-Link DCS-700L IP cameras running firmware version 1.03.09. Attackers on the local network can e...

Jan 28, 2026
CVE-2025-4661
2.3

A path traversal vulnerability in Brocade Fabric OS allows local admin users to access files outside intended directories, potentially exposing sensit...

Jun 19, 2025
CVE-2026-27735
N/A

This vulnerability allows attackers to stage files outside the repository boundaries using path traversal sequences (../) in the git_add tool. It affe...

Feb 26, 2026
CVE-2026-2731
N/A

This vulnerability allows unauthenticated attackers to perform path traversal and content injection in DynamicWeb's JobRunnerBackground.aspx file, lea...

Feb 19, 2026
CVE-2026-2464
N/A

This is an unauthenticated path traversal vulnerability in AMR Printer Management 1.01 Beta web service that allows attackers to read arbitrary files ...

Feb 18, 2026
CVE-2026-1523
N/A

A path traversal vulnerability in Digitek ADT1100 and DT950 devices allows attackers to access arbitrary files on the server's file system by manipula...

Feb 5, 2026
CVE-2025-65077
N/A

A relative path traversal vulnerability in Lexmark's Embedded Solutions Framework allows attackers to access files outside intended directories and ex...

Feb 3, 2026
CVE-2025-61658
N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to sensitive user contribution data. It affects administra...

Feb 3, 2026
CVE-2025-61653
N/A

This vulnerability in Wikimedia Foundation's TextExtracts extension allows attackers to execute arbitrary code or access sensitive data through improp...

Feb 3, 2026
CVE-2025-61654
N/A

This vulnerability in Wikimedia Foundation's Thanks extension allows attackers to execute unauthorized actions through the ThanksQueryHelper.php file....

Feb 3, 2026
CVE-2025-61646
N/A

This vulnerability in MediaWiki's EnhancedChangesList.php allows attackers to potentially execute unauthorized actions or access sensitive data throug...

Feb 3, 2026
CVE-2025-61649
N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to user information. It affects systems running CheckUser ...

Feb 3, 2026
CVE-2025-61641
N/A

This vulnerability in MediaWiki's ApiQueryAllPages.php allows attackers to potentially access or manipulate page data through the API. It affects Medi...

Feb 3, 2026
CVE-2025-61647
N/A

This vulnerability in Wikimedia Foundation's CheckUser extension allows unauthorized access to user information through the UserInfoHandler API endpoi...

Feb 3, 2026
CVE-2025-6597
N/A

This vulnerability in MediaWiki's AuthManager.php allows attackers to bypass authentication mechanisms under specific conditions. It affects all Media...

Feb 2, 2026
CVE-2025-6927
N/A

This vulnerability in MediaWiki's block list functionality could allow attackers to access sensitive information or perform unauthorized actions. It a...

Feb 2, 2026
CVE-2026-1703
N/A

This CVE describes a path traversal vulnerability in pip's wheel archive extraction. When installing a maliciously crafted wheel file, attackers can w...

Feb 2, 2026
CVE-2026-1186
N/A

EAP Legislator contains a path traversal vulnerability in its file extraction functionality. Attackers can craft malicious zipx archives that, when op...

Feb 2, 2026

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,221 CVEs classified as CWE-22, with 535 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free