CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (2,225)
This vulnerability in MediaWiki's AuthManager.php allows attackers to bypass authentication mechanisms under specific conditions. It affects all Media...
Feb 2, 2026This vulnerability in MediaWiki's block list functionality could allow attackers to access sensitive information or perform unauthorized actions. It a...
Feb 2, 2026This CVE describes a path traversal vulnerability in pip's wheel archive extraction. When installing a maliciously crafted wheel file, attackers can w...
Feb 2, 2026EAP Legislator contains a path traversal vulnerability in its file extraction functionality. Attackers can craft malicious zipx archives that, when op...
Feb 2, 2026SunFounder Pironman Dashboard versions 1.3.13 and earlier contain an unauthenticated path traversal vulnerability in log file API endpoints. Attackers...
Feb 1, 2026This vulnerability in Ralim IronOS affects the ECC/DSA cryptographic implementation in the Pinecilv2 Bluetooth stack. It could allow attackers to comp...
Jan 27, 2026EduSoho versions before 22.4.7 contain an unauthenticated path traversal vulnerability in the classroom-course-statistics export feature. Attackers ca...
Jan 22, 2026A path traversal vulnerability in AdonisJS multipart file handling allows remote attackers to write arbitrary files to arbitrary locations on the serv...
Jan 2, 2026A path traversal vulnerability (CWE-22) in QNAP software for macOS allows local attackers with user accounts to read arbitrary files or system data. T...
Jan 2, 2026An arbitrary file read vulnerability in KEDA allows attackers with permissions to create or modify TriggerAuthentication resources to read any file fr...
Dec 22, 2025This vulnerability in Streama allows authenticated attackers to write arbitrary files to the server filesystem by exploiting path traversal and SSRF i...
Dec 18, 2025The git_init tool in mcp-server-git versions prior to 2025.9.25 allowed arbitrary filesystem path creation of Git repositories without validation. Thi...
Dec 17, 2025This vulnerability allows mcp-server-git instances configured with the --repository flag to bypass path restrictions and perform git operations on una...
Dec 17, 2025NetSupport Manager versions before 14.12.0001 contain an authenticated path traversal vulnerability in the Connectivity Server/Gateway's PUTFILE handl...
Dec 15, 2025APC Network Management Card 4 contains an unauthenticated path traversal vulnerability that allows attackers to read sensitive system files like /etc/...
Dec 11, 2025This path traversal vulnerability in JMRI allows attackers to access files outside the intended directory by manipulating file paths. It affects all J...
Dec 9, 2025A path traversal vulnerability in Console (a network control system for Gorilla Tag mods) allows attackers to escape the intended directory structure ...
Nov 25, 2025A path traversal vulnerability in certain ASUS router models allows authenticated remote attackers to write files outside intended directories. This c...
Nov 25, 2025An authentication bypass vulnerability in AiCloud allows attackers to execute specific functions without proper authorization by exploiting an uninten...
Nov 25, 2025A path traversal vulnerability in WebDAV allows unauthenticated remote attackers to access or modify files outside intended directories. This affects ...
Nov 25, 2025This vulnerability allows unauthenticated attackers to perform directory traversal attacks on BASIS BBj servers, reading arbitrary system files access...
Nov 20, 2025A path traversal vulnerability in Schneider Electric systems allows local network Web Admin users to manipulate file paths via POST /REST/UpdateJRE re...
Nov 12, 2025A local server-side request forgery vulnerability in Studio 5000 Simulation Interface allows any Windows user on the system to trigger outbound SMB re...
Nov 11, 2025A path traversal vulnerability in CVAT allows authenticated users with at least User role to create or overwrite files in the root of mounted file sha...
Nov 8, 2025CVE-2025-64346 is a path traversal vulnerability in the archives Go library that allows attackers to achieve remote code execution or file modificatio...
Nov 7, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 2,225 CVEs classified as CWE-22, with 539 rated critical and 1,138 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free