CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,977
Total CVEs
443
Critical
995
High
7.6
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Siemens 15
8 Adobe 15
9 Fedoraproject 14
10 Ibm 13

All Path Traversal CVEs (1,977)

CVE-2021-43290
9.8

This vulnerability allows an attacker who has compromised a GoCD agent to upload malicious files to a GoCD server directory. While they can control th...

Apr 14, 2022
CVE-2021-43741
9.8

CMSimple 5.4 contains a directory traversal vulnerability in config.php that allows attackers to manipulate file names to execute arbitrary code remot...

Apr 13, 2022
CVE-2022-0679
9.8

The Narnoo Distributor WordPress plugin through version 2.5.1 contains a path traversal vulnerability that allows attackers to read arbitrary files on...

Mar 28, 2022
CVE-2022-1000
9.8

This path traversal vulnerability in tinyfilemanager allows attackers to access files outside the intended directory by manipulating file paths. It af...

Mar 17, 2022
CVE-2021-45887
9.8

This vulnerability allows authenticated administrators of PONTON X/P Messenger to upload ZIP files containing executable scripts via a path traversal ...

Mar 13, 2022
CVE-2021-3762
9.8

A directory traversal vulnerability in ClairCore allows attackers to write arbitrary files to the filesystem by uploading a malicious container image....

Mar 3, 2022
CVE-2022-24312
9.8

This vulnerability allows attackers to write arbitrary files to the Schneider Electric Interactive Graphical SCADA System Data Server through path tra...

Feb 9, 2022
CVE-2022-0320
9.8

This vulnerability in the Essential Addons for Elementor WordPress plugin allows unauthenticated attackers to perform Local File Inclusion attacks, re...

Feb 1, 2022
CVE-2021-23484
9.8

This vulnerability allows attackers to write arbitrary files outside the intended extraction directory when extracting ZIP archives using zip-local. T...

Jan 28, 2022
CVE-2021-37128
9.8

CVE-2021-37128 is a path traversal vulnerability in HwPCAssistant that allows attackers to write arbitrary files to the filesystem. This affects Huawe...

Jan 3, 2022
CVE-2021-45427
9.8

CVE-2021-45427 allows unauthenticated attackers to delete arbitrary files on Emerson XWEB 300D EVO systems due to path traversal vulnerabilities and i...

Dec 30, 2021
CVE-2021-31746
9.8

CVE-2021-31746 is a Zip Slip vulnerability in Pluck-CMS that allows attackers to upload malicious zip files containing directory traversal paths. When...

Dec 10, 2021
CVE-2021-43676
9.8

CVE-2021-43676 is a path manipulation vulnerability in the matyhtf framework's Smarty.class.php that allows attackers to read arbitrary files on the s...

Dec 3, 2021
CVE-2021-43674
9.8

ThinkUp 2.0-beta.10 contains a path manipulation vulnerability in Smarty.class.php that allows attackers to potentially read arbitrary files on the se...

Dec 3, 2021
CVE-2021-43691
9.8

CVE-2021-43691 is a path traversal vulnerability in tripexpress v1.1 that allows attackers to write arbitrary files to the server filesystem by manipu...

Nov 29, 2021
CVE-2021-29212
9.8

CVE-2021-29212 is a critical directory traversal vulnerability in HPE iLO Amplifier Pack that allows unauthenticated remote attackers to execute arbit...

Nov 1, 2021
CVE-2021-40371
9.8

This vulnerability allows attackers to perform directory traversal attacks in Gridpro Request Management for Windows Azure Pack, potentially leading t...

Oct 25, 2021
CVE-2021-40887
9.8

CVE-2021-40887 is a critical directory traversal vulnerability in ProjectSend file sharing software that allows attackers to upload arbitrary files to...

Oct 11, 2021
CVE-2021-42013
9.8

CVE-2021-42013 is a critical path traversal vulnerability in Apache HTTP Server that allows attackers to access files outside configured directories. ...

Oct 7, 2021
CVE-2021-41773
9.8

CVE-2021-41773 is a path traversal vulnerability in Apache HTTP Server 2.4.49 that allows attackers to access files outside configured directories. If...

Oct 5, 2021
CVE-2021-40098
9.8

This vulnerability in Concrete CMS allows attackers to perform path traversal attacks through external forms, leading to remote code execution. It aff...

Sep 27, 2021
CVE-2021-22005
9.8

CVE-2021-22005 is a critical arbitrary file upload vulnerability in VMware vCenter Server's Analytics service. Attackers with network access to port 4...

Sep 23, 2021
CVE-2021-27341
9.8

OpenSIS Community Edition versions up to 7.6 contain a local file inclusion vulnerability in DownloadWindow.php via the 'filename' parameter. This all...

Sep 16, 2021
CVE-2021-38197
9.8

This vulnerability in go-unarr 0.1.1 allows attackers to perform directory traversal attacks via specially crafted TAR archives containing '../' seque...

Aug 8, 2021
CVE-2020-19305
9.8

This vulnerability in Metinfo CMS allows attackers to escalate privileges by exploiting improper path handling when deleting columns. Attackers can de...

Aug 3, 2021
CVE-2021-31272
9.8

This vulnerability in SerenityOS allows attackers to exploit directory traversal in tar/unzip utilities, potentially leading to arbitrary command exec...

Jun 18, 2021
CVE-2021-33576
9.8

CVE-2021-33576 is a path traversal vulnerability in Cleo LexiCom AS2 file transfer software. Attackers can manipulate filenames in AS2 messages to wri...

Jun 18, 2021
CVE-2020-18178
9.8

CVE-2020-18178 is a critical path traversal vulnerability in HongCMS v4.0.0 that allows remote attackers to read, modify, or delete arbitrary files on...

May 18, 2021
CVE-2021-31800
9.8

CVE-2021-31800 is a critical path traversal vulnerability in Impacket's SMB server (smbserver.py) that allows attackers to read and write arbitrary fi...

May 5, 2021
CVE-2021-28959
9.8

CVE-2021-28959 is a critical directory traversal vulnerability in Zoho ManageEngine Eventlog Analyzer that allows unauthenticated attackers to upload ...

Apr 30, 2021
CVE-2021-20090
9.8

This CVE describes an unauthenticated path traversal vulnerability in Buffalo router web interfaces that allows attackers to bypass authentication mec...

Apr 29, 2021
CVE-2021-29417
9.8

CVE-2021-29417 is a critical directory traversal vulnerability in gitjacker versions before 0.1.0 that allows remote attackers to execute arbitrary co...

Mar 29, 2021
CVE-2021-26293
9.8

This vulnerability allows attackers to perform directory traversal attacks when DAV is enabled in AfterLogic Aurora and WebMail Pro. Attackers can cre...

Mar 4, 2021
CVE-2021-21972
9.8

CVE-2021-21972 is a critical remote code execution vulnerability in VMware vSphere Client's HTML5 interface. It allows unauthenticated attackers with ...

Feb 24, 2021
CVE-2021-3199
9.8

CVE-2021-3199 is a critical directory traversal vulnerability in ONLYOFFICE Document Server that allows authenticated attackers to upload malicious fi...

Jan 26, 2021
CVE-2020-27637
9.8

CVE-2020-27637 is a critical path traversal vulnerability in CRAN, R's default package manager, that allows attackers to write arbitrary files outside...

Jan 12, 2021
CVE-2020-13450
9.8

CVE-2020-13450 is a critical directory traversal vulnerability in Gotenberg's file upload function that allows attackers to upload and overwrite files...

Jan 7, 2021
CVE-2020-36052
9.8

This directory traversal vulnerability in MiniCMS V1.10 allows remote attackers to include and execute arbitrary files via the state parameter in post...

Jan 5, 2021
CVE-2020-28187
9.8

CVE-2020-28187 is a critical directory traversal vulnerability in TerraMaster TOS that allows authenticated attackers to read, edit, or delete any fil...

Dec 24, 2020
CVE-2020-5639
9.8

CVE-2020-5639 is a directory traversal vulnerability in FileZen file transfer software that allows remote attackers to upload arbitrary files to speci...

Dec 14, 2020
CVE-2020-27730
9.8

This vulnerability in NGINX Controller Agent versions 1.0.1, 2.0.0-2.9.0, and 3.0.0-3.9.0 allows attackers to execute arbitrary code with root privile...

Dec 11, 2020
CVE-2017-15681
9.8

CVE-2017-15681 is a critical directory traversal vulnerability in Crafter CMS Crafter Studio 3.0.1 that allows unauthenticated attackers to overwrite ...

Nov 27, 2020
CVE-2020-15929
9.8

CVE-2020-15929 is a critical path traversal vulnerability in Ortus TestBox that allows unauthenticated attackers to write arbitrary CFM files containi...

Nov 24, 2020
CVE-2020-12315
9.8

A path traversal vulnerability in Intel EMA (Endpoint Management Assistant) allows unauthenticated attackers to access files outside intended director...

Nov 12, 2020
CVE-2020-25074
9.8

CVE-2020-25074 is a directory traversal vulnerability in MoinMoin's cache action that allows attackers who can upload attachments to execute arbitrary...

Nov 10, 2020
CVE-2020-27160
9.8

This is a critical remote code execution vulnerability in Western Digital My Cloud NAS devices that allows attackers to execute arbitrary code with el...

Oct 27, 2020
CVE-2020-21526
9.8

CVE-2020-21526 is a critical directory traversal vulnerability in Halo v1.1.3 that allows authenticated attackers to write arbitrary files to the serv...

Sep 30, 2020
CVE-2020-21522
9.8

CVE-2020-21522 is a Zip Slip directory traversal vulnerability in Halo CMS version 1.1.3 that allows attackers to overwrite critical system files thro...

Sep 30, 2020
CVE-2020-24626
9.8

This vulnerability allows unauthenticated attackers to perform directory traversal attacks via the ReceiverServlet class in HPE Pay Per Use Utility Co...

Sep 23, 2020
CVE-2025-10283
9.6

CVE-2025-10283 is a path traversal vulnerability in BBOT's gitdumper module that allows remote code execution when processing malicious git repositori...

Oct 9, 2025

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,977 CVEs classified as CWE-22, with 443 rated critical and 995 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free