CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

2,225
Total CVEs
539
Critical
1,138
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
249
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 27
2 Qnap 22
3 Fedoraproject 20
4 Ivanti 19
5 Debian 19
6 Solarwinds 17
7 Fortinet 17
8 Adobe 17
9 Siemens 16
10 Samsung 16

All Path Traversal CVEs (2,225)

CVE-2025-6597
N/A

This vulnerability in MediaWiki's AuthManager.php allows attackers to bypass authentication mechanisms under specific conditions. It affects all Media...

Feb 2, 2026
CVE-2025-6927
N/A

This vulnerability in MediaWiki's block list functionality could allow attackers to access sensitive information or perform unauthorized actions. It a...

Feb 2, 2026
CVE-2026-1703
N/A

This CVE describes a path traversal vulnerability in pip's wheel archive extraction. When installing a maliciously crafted wheel file, attackers can w...

Feb 2, 2026
CVE-2026-1186
N/A

EAP Legislator contains a path traversal vulnerability in its file extraction functionality. Attackers can craft malicious zipx archives that, when op...

Feb 2, 2026
CVE-2026-25069
N/A

SunFounder Pironman Dashboard versions 1.3.13 and earlier contain an unauthenticated path traversal vulnerability in log file API endpoints. Attackers...

Feb 1, 2026
CVE-2026-24801
N/A

This vulnerability in Ralim IronOS affects the ECC/DSA cryptographic implementation in the Pinecilv2 Bluetooth stack. It could allow attackers to comp...

Jan 27, 2026
CVE-2023-7335
N/A

EduSoho versions before 22.4.7 contain an unauthenticated path traversal vulnerability in the classroom-course-statistics export feature. Attackers ca...

Jan 22, 2026
CVE-2026-21440
N/A

A path traversal vulnerability in AdonisJS multipart file handling allows remote attackers to write arbitrary files to arbitrary locations on the serv...

Jan 2, 2026
CVE-2025-53594
N/A

A path traversal vulnerability (CWE-22) in QNAP software for macOS allows local attackers with user accounts to read arbitrary files or system data. T...

Jan 2, 2026
CVE-2025-68476
N/A

An arbitrary file read vulnerability in KEDA allows attackers with permissions to create or modify TriggerAuthentication resources to read any file fr...

Dec 22, 2025
CVE-2025-34452
N/A

This vulnerability in Streama allows authenticated attackers to write arbitrary files to the server filesystem by exploiting path traversal and SSRF i...

Dec 18, 2025
CVE-2025-68143
N/A

The git_init tool in mcp-server-git versions prior to 2025.9.25 allowed arbitrary filesystem path creation of Git repositories without validation. Thi...

Dec 17, 2025
CVE-2025-68145
N/A

This vulnerability allows mcp-server-git instances configured with the --repository flag to bypass path restrictions and perform git operations on una...

Dec 17, 2025
CVE-2025-34181
N/A

NetSupport Manager versions before 14.12.0001 contain an authenticated path traversal vulnerability in the Connectivity Server/Gateway's PUTFILE handl...

Dec 15, 2025
CVE-2024-58310
N/A

APC Network Management Card 4 contains an unauthenticated path traversal vulnerability that allows attackers to read sensitive system files like /etc/...

Dec 11, 2025
CVE-2025-14311
N/A

This path traversal vulnerability in JMRI allows attackers to access files outside the intended directory by manipulating file paths. It affects all J...

Dec 9, 2025
CVE-2025-65952
N/A

A path traversal vulnerability in Console (a network control system for Gorilla Tag mods) allows attackers to escape the intended directory structure ...

Nov 25, 2025
CVE-2025-59372
N/A

A path traversal vulnerability in certain ASUS router models allows authenticated remote attackers to write files outside intended directories. This c...

Nov 25, 2025
CVE-2025-59366
N/A

An authentication bypass vulnerability in AiCloud allows attackers to execute specific functions without proper authorization by exploiting an uninten...

Nov 25, 2025
CVE-2025-12003
N/A

A path traversal vulnerability in WebDAV allows unauthenticated remote attackers to access or modify files outside intended directories. This affects ...

Nov 25, 2025
CVE-2025-34320
N/A

This vulnerability allows unauthenticated attackers to perform directory traversal attacks on BASIS BBj servers, reading arbitrary system files access...

Nov 20, 2025
CVE-2025-11565
N/A

A path traversal vulnerability in Schneider Electric systems allows local network Web Admin users to manipulate file paths via POST /REST/UpdateJRE re...

Nov 12, 2025
CVE-2025-11696
N/A

A local server-side request forgery vulnerability in Studio 5000 Simulation Interface allows any Windows user on the system to trigger outbound SMB re...

Nov 11, 2025
CVE-2025-64485
N/A

A path traversal vulnerability in CVAT allows authenticated users with at least User role to create or overwrite files in the root of mounted file sha...

Nov 8, 2025
CVE-2025-64346
N/A

CVE-2025-64346 is a path traversal vulnerability in the archives Go library that allows attackers to achieve remote code execution or file modificatio...

Nov 7, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 2,225 CVEs classified as CWE-22, with 539 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free