CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (1,977)
This vulnerability allows an attacker who has compromised a GoCD agent to upload malicious files to a GoCD server directory. While they can control th...
Apr 14, 2022CMSimple 5.4 contains a directory traversal vulnerability in config.php that allows attackers to manipulate file names to execute arbitrary code remot...
Apr 13, 2022The Narnoo Distributor WordPress plugin through version 2.5.1 contains a path traversal vulnerability that allows attackers to read arbitrary files on...
Mar 28, 2022This path traversal vulnerability in tinyfilemanager allows attackers to access files outside the intended directory by manipulating file paths. It af...
Mar 17, 2022This vulnerability allows authenticated administrators of PONTON X/P Messenger to upload ZIP files containing executable scripts via a path traversal ...
Mar 13, 2022A directory traversal vulnerability in ClairCore allows attackers to write arbitrary files to the filesystem by uploading a malicious container image....
Mar 3, 2022This vulnerability allows attackers to write arbitrary files to the Schneider Electric Interactive Graphical SCADA System Data Server through path tra...
Feb 9, 2022This vulnerability in the Essential Addons for Elementor WordPress plugin allows unauthenticated attackers to perform Local File Inclusion attacks, re...
Feb 1, 2022This vulnerability allows attackers to write arbitrary files outside the intended extraction directory when extracting ZIP archives using zip-local. T...
Jan 28, 2022CVE-2021-37128 is a path traversal vulnerability in HwPCAssistant that allows attackers to write arbitrary files to the filesystem. This affects Huawe...
Jan 3, 2022CVE-2021-45427 allows unauthenticated attackers to delete arbitrary files on Emerson XWEB 300D EVO systems due to path traversal vulnerabilities and i...
Dec 30, 2021CVE-2021-31746 is a Zip Slip vulnerability in Pluck-CMS that allows attackers to upload malicious zip files containing directory traversal paths. When...
Dec 10, 2021CVE-2021-43676 is a path manipulation vulnerability in the matyhtf framework's Smarty.class.php that allows attackers to read arbitrary files on the s...
Dec 3, 2021ThinkUp 2.0-beta.10 contains a path manipulation vulnerability in Smarty.class.php that allows attackers to potentially read arbitrary files on the se...
Dec 3, 2021CVE-2021-43691 is a path traversal vulnerability in tripexpress v1.1 that allows attackers to write arbitrary files to the server filesystem by manipu...
Nov 29, 2021CVE-2021-29212 is a critical directory traversal vulnerability in HPE iLO Amplifier Pack that allows unauthenticated remote attackers to execute arbit...
Nov 1, 2021This vulnerability allows attackers to perform directory traversal attacks in Gridpro Request Management for Windows Azure Pack, potentially leading t...
Oct 25, 2021CVE-2021-40887 is a critical directory traversal vulnerability in ProjectSend file sharing software that allows attackers to upload arbitrary files to...
Oct 11, 2021CVE-2021-42013 is a critical path traversal vulnerability in Apache HTTP Server that allows attackers to access files outside configured directories. ...
Oct 7, 2021CVE-2021-41773 is a path traversal vulnerability in Apache HTTP Server 2.4.49 that allows attackers to access files outside configured directories. If...
Oct 5, 2021This vulnerability in Concrete CMS allows attackers to perform path traversal attacks through external forms, leading to remote code execution. It aff...
Sep 27, 2021CVE-2021-22005 is a critical arbitrary file upload vulnerability in VMware vCenter Server's Analytics service. Attackers with network access to port 4...
Sep 23, 2021OpenSIS Community Edition versions up to 7.6 contain a local file inclusion vulnerability in DownloadWindow.php via the 'filename' parameter. This all...
Sep 16, 2021This vulnerability in go-unarr 0.1.1 allows attackers to perform directory traversal attacks via specially crafted TAR archives containing '../' seque...
Aug 8, 2021This vulnerability in Metinfo CMS allows attackers to escalate privileges by exploiting improper path handling when deleting columns. Attackers can de...
Aug 3, 2021This vulnerability in SerenityOS allows attackers to exploit directory traversal in tar/unzip utilities, potentially leading to arbitrary command exec...
Jun 18, 2021CVE-2021-33576 is a path traversal vulnerability in Cleo LexiCom AS2 file transfer software. Attackers can manipulate filenames in AS2 messages to wri...
Jun 18, 2021CVE-2020-18178 is a critical path traversal vulnerability in HongCMS v4.0.0 that allows remote attackers to read, modify, or delete arbitrary files on...
May 18, 2021CVE-2021-31800 is a critical path traversal vulnerability in Impacket's SMB server (smbserver.py) that allows attackers to read and write arbitrary fi...
May 5, 2021CVE-2021-28959 is a critical directory traversal vulnerability in Zoho ManageEngine Eventlog Analyzer that allows unauthenticated attackers to upload ...
Apr 30, 2021This CVE describes an unauthenticated path traversal vulnerability in Buffalo router web interfaces that allows attackers to bypass authentication mec...
Apr 29, 2021CVE-2021-29417 is a critical directory traversal vulnerability in gitjacker versions before 0.1.0 that allows remote attackers to execute arbitrary co...
Mar 29, 2021This vulnerability allows attackers to perform directory traversal attacks when DAV is enabled in AfterLogic Aurora and WebMail Pro. Attackers can cre...
Mar 4, 2021CVE-2021-21972 is a critical remote code execution vulnerability in VMware vSphere Client's HTML5 interface. It allows unauthenticated attackers with ...
Feb 24, 2021CVE-2021-3199 is a critical directory traversal vulnerability in ONLYOFFICE Document Server that allows authenticated attackers to upload malicious fi...
Jan 26, 2021CVE-2020-27637 is a critical path traversal vulnerability in CRAN, R's default package manager, that allows attackers to write arbitrary files outside...
Jan 12, 2021CVE-2020-13450 is a critical directory traversal vulnerability in Gotenberg's file upload function that allows attackers to upload and overwrite files...
Jan 7, 2021This directory traversal vulnerability in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter in post...
Jan 5, 2021CVE-2020-28187 is a critical directory traversal vulnerability in TerraMaster TOS that allows authenticated attackers to read, edit, or delete any fil...
Dec 24, 2020CVE-2020-5639 is a directory traversal vulnerability in FileZen file transfer software that allows remote attackers to upload arbitrary files to speci...
Dec 14, 2020This vulnerability in NGINX Controller Agent versions 1.0.1, 2.0.0-2.9.0, and 3.0.0-3.9.0 allows attackers to execute arbitrary code with root privile...
Dec 11, 2020CVE-2017-15681 is a critical directory traversal vulnerability in Crafter CMS Crafter Studio 3.0.1 that allows unauthenticated attackers to overwrite ...
Nov 27, 2020CVE-2020-15929 is a critical path traversal vulnerability in Ortus TestBox that allows unauthenticated attackers to write arbitrary CFM files containi...
Nov 24, 2020A path traversal vulnerability in Intel EMA (Endpoint Management Assistant) allows unauthenticated attackers to access files outside intended director...
Nov 12, 2020CVE-2020-25074 is a directory traversal vulnerability in MoinMoin's cache action that allows attackers who can upload attachments to execute arbitrary...
Nov 10, 2020This is a critical remote code execution vulnerability in Western Digital My Cloud NAS devices that allows attackers to execute arbitrary code with el...
Oct 27, 2020CVE-2020-21526 is a critical directory traversal vulnerability in Halo v1.1.3 that allows authenticated attackers to write arbitrary files to the serv...
Sep 30, 2020CVE-2020-21522 is a Zip Slip directory traversal vulnerability in Halo CMS version 1.1.3 that allows attackers to overwrite critical system files thro...
Sep 30, 2020This vulnerability allows unauthenticated attackers to perform directory traversal attacks via the ReceiverServlet class in HPE Pay Per Use Utility Co...
Sep 23, 2020CVE-2025-10283 is a path traversal vulnerability in BBOT's gitdumper module that allows remote code execution when processing malicious git repositori...
Oct 9, 2025About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 1,977 CVEs classified as CWE-22, with 443 rated critical and 995 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free