CWE-22: Path Traversal
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Yearly Trend
Top Affected Vendors
All Path Traversal CVEs (1,982)
This critical vulnerability in Advantech iView allows attackers to bypass path restrictions and access arbitrary files on the system. It affects all v...
Aug 25, 2020CVE-2025-10283 is a path traversal vulnerability in BBOT's gitdumper module that allows remote code execution when processing malicious git repositori...
Oct 9, 2025CVE-2024-38824 is a critical directory traversal vulnerability in SaltStack's recv_file method that allows attackers to write arbitrary files to the m...
Jun 13, 2025CVE-2025-24891 is a critical path traversal vulnerability in Dumb Drop file upload application that allows authenticated users to overwrite arbitrary ...
Jan 31, 2025This path traversal vulnerability in the SSV Events WordPress plugin allows attackers to include arbitrary local PHP files, potentially leading to rem...
Oct 20, 2024This vulnerability allows attackers to perform path traversal attacks in Vmaxstudio Vmax Project Manager WordPress plugin, leading to local file inclu...
Oct 5, 2024CVE-2024-23475 is a critical directory traversal vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to delete arb...
Jul 17, 2024This vulnerability allows unauthenticated attackers to traverse directories and execute arbitrary code with SYSTEM privileges on SolarWinds Access Rig...
Jul 17, 2024This CVE describes a path traversal vulnerability (CWE-22) in QNAP Media Streaming add-on that allows attackers to access sensitive files on the syste...
Apr 26, 2024SolarWinds Access Rights Manager (ARM) contains a directory traversal vulnerability that allows unauthenticated attackers to execute arbitrary code re...
Feb 15, 2024SolarWinds Access Rights Manager (ARM) contains a directory traversal vulnerability that allows unauthenticated attackers to execute arbitrary code re...
Feb 15, 2024This vulnerability in the AI ChatBot for WordPress plugin allows attackers with subscriber-level access to perform directory traversal and append PHP ...
Oct 19, 2023This vulnerability allows authenticated non-administrative users to exploit a directory traversal flaw in SAPRSBRO program to overwrite critical syste...
Mar 14, 2023This CVE allows attackers with non-administrative SAP authorizations to exploit a directory traversal vulnerability in SAP NetWeaver ABAP services. At...
Mar 14, 2023This vulnerability in Marvell QConvergeConsole allows unauthenticated remote attackers to delete arbitrary files and read sensitive information by exp...
Jul 7, 2025This vulnerability in Python's tarfile module allows attackers to write arbitrary files outside the intended extraction directory when extracting untr...
Jun 3, 2025This is a path traversal vulnerability in Ivanti CSA (Cloud Services Appliance) that allows remote unauthenticated attackers to bypass security restri...
Sep 19, 2024A directory traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart allows attackers to read or write arbitrary files via the IEC61850 File Transfe...
Jun 27, 2024CVE-2024-0964 is a critical local file inclusion vulnerability in Gradio that allows remote attackers to read arbitrary files on the server by exploit...
Feb 5, 2024Mammoth document conversion library versions before 1.11.0 are vulnerable to directory traversal attacks when processing DOCX files containing images ...
Oct 17, 2025This vulnerability in the WordPress Automatic plugin allows unauthenticated attackers to perform path traversal attacks, potentially downloading arbit...
May 17, 2024CVE-2023-50255 is a path traversal vulnerability in Deepin-Compressor, the default archive manager for Deepin Linux OS. When users open specially craf...
Dec 27, 2023A path traversal vulnerability in Zoom Desktop Client for Windows allows unauthenticated attackers to escalate privileges via network access. This aff...
Aug 8, 2023This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the heidi-luong1109/shackerpanel reposito...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the ralphjzhang/iasset repository. It aff...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the OpenMF application. It affects any de...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the AutomatedQuizEval repository. It affe...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the umeshpatil-dev/Home__internet repository, enabling unauthorized ...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks by exploiting unsafe usage of Flask's send_file function in the yuriyou...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the pleomax00/flask-mongo-skel repository, enabling unauthorized fil...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the rainsoupah/sleep-learner GitHub repos...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the romain20100/nursequest repository. It...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the seveas/golem repository, enabling unauthorized file access. It a...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the tsileo/flask-yeoman repository, enabling unauthorized file acces...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the varijkapil13/Sphere_ImageBackend repository, enabling unauthoriz...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the whmacmac/vprj GitHub repository, enabling unauthorized file acce...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the yogson/syrabond repository. It affect...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through path traversal in the DSABenchmark/DSAB repository. It affects users...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the ceee-vip/cockybook repository, enabling unauthorized file access...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the deepaliupadhyay/RealEstate repository due to unsafe use of Flask...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server by exploiting path traversal in the Fishtank repository's Flask application....
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server by exploiting path traversal in the Flask send_file function. It affects any...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the kotekan/kotekan repository, enabling unauthorized file access. I...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the Barry Voice Assistant Flask applicati...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the SetupBox repository. It affects any s...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the ml-inory/ModelConverter repository. I...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the noamezekiel/sphere repository. It aff...
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the olmax99/helm-flask-celery repository....
Jul 11, 2022This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the SummaLabs/DLS repository. It affects ...
Jul 11, 2022This vulnerability allows attackers to perform absolute path traversal attacks in the Wildog/flask-file-server repository, enabling unauthorized file ...
Jul 11, 2022About Path Traversal (CWE-22)
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.
Our database tracks 1,982 CVEs classified as CWE-22, with 445 rated critical and 998 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.
External reference: View CWE-22 on MITRE CWE →
Monitor Path Traversal Vulnerabilities
Get alerted when new Path Traversal CVEs affect your infrastructure.
Start Monitoring Free