CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,982
Total CVEs
445
Critical
998
High
7.6
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Siemens 15
8 Adobe 15
9 Fedoraproject 15
10 Ibm 13

All Path Traversal CVEs (1,982)

CVE-2020-16245
9.8

This critical vulnerability in Advantech iView allows attackers to bypass path restrictions and access arbitrary files on the system. It affects all v...

Aug 25, 2020
CVE-2025-10283
9.6

CVE-2025-10283 is a path traversal vulnerability in BBOT's gitdumper module that allows remote code execution when processing malicious git repositori...

Oct 9, 2025
CVE-2024-38824
9.6

CVE-2024-38824 is a critical directory traversal vulnerability in SaltStack's recv_file method that allows attackers to write arbitrary files to the m...

Jun 13, 2025
CVE-2025-24891
9.6

CVE-2025-24891 is a critical path traversal vulnerability in Dumb Drop file upload application that allows authenticated users to overwrite arbitrary ...

Jan 31, 2025
CVE-2024-49286
9.6

This path traversal vulnerability in the SSV Events WordPress plugin allows attackers to include arbitrary local PHP files, potentially leading to rem...

Oct 20, 2024
CVE-2024-44014
9.6

This vulnerability allows attackers to perform path traversal attacks in Vmaxstudio Vmax Project Manager WordPress plugin, leading to local file inclu...

Oct 5, 2024
CVE-2024-23475
9.6

CVE-2024-23475 is a critical directory traversal vulnerability in SolarWinds Access Rights Manager that allows unauthenticated attackers to delete arb...

Jul 17, 2024
CVE-2024-23466
9.6

This vulnerability allows unauthenticated attackers to traverse directories and execute arbitrary code with SYSTEM privileges on SolarWinds Access Rig...

Jul 17, 2024
CVE-2023-47222
9.6

This CVE describes a path traversal vulnerability (CWE-22) in QNAP Media Streaming add-on that allows attackers to access sensitive files on the syste...

Apr 26, 2024
CVE-2024-23479
9.6

SolarWinds Access Rights Manager (ARM) contains a directory traversal vulnerability that allows unauthenticated attackers to execute arbitrary code re...

Feb 15, 2024
CVE-2024-23476
9.6

SolarWinds Access Rights Manager (ARM) contains a directory traversal vulnerability that allows unauthenticated attackers to execute arbitrary code re...

Feb 15, 2024
CVE-2023-5241
9.6

This vulnerability in the AI ChatBot for WordPress plugin allows attackers with subscriber-level access to perform directory traversal and append PHP ...

Oct 19, 2023
CVE-2023-27500
9.6

This vulnerability allows authenticated non-administrative users to exploit a directory traversal flaw in SAPRSBRO program to overwrite critical syste...

Mar 14, 2023
CVE-2023-27269
9.6

This CVE allows attackers with non-administrative SAP authorizations to exploit a directory traversal vulnerability in SAP NetWeaver ABAP services. At...

Mar 14, 2023
CVE-2025-6793
EPSS 21.8% 9.4

This vulnerability in Marvell QConvergeConsole allows unauthenticated remote attackers to delete arbitrary files and read sensitive information by exp...

Jul 7, 2025
CVE-2025-4517
9.4

This vulnerability in Python's tarfile module allows attackers to write arbitrary files outside the intended extraction directory when extracting untr...

Jun 3, 2025
CVE-2024-8963
9.4

This is a path traversal vulnerability in Ivanti CSA (Cloud Services Appliance) that allows remote unauthenticated attackers to bypass security restri...

Sep 19, 2024
CVE-2024-36059
9.4

A directory traversal vulnerability in Kalkitech ASE ASE61850 IEDSmart allows attackers to read or write arbitrary files via the IEC61850 File Transfe...

Jun 27, 2024
CVE-2024-0964
9.4

CVE-2024-0964 is a critical local file inclusion vulnerability in Gradio that allows remote attackers to read arbitrary files on the server by exploit...

Feb 5, 2024
CVE-2025-11849
9.3

Mammoth document conversion library versions before 1.11.0 are vulnerable to directory traversal attacks when processing DOCX files containing images ...

Oct 17, 2025
CVE-2024-27954
9.3

This vulnerability in the WordPress Automatic plugin allows unauthenticated attackers to perform path traversal attacks, potentially downloading arbit...

May 17, 2024
CVE-2023-50255
9.3

CVE-2023-50255 is a path traversal vulnerability in Deepin-Compressor, the default archive manager for Deepin Linux OS. When users open specially craf...

Dec 27, 2023
CVE-2023-36534
9.3

A path traversal vulnerability in Zoom Desktop Client for Windows allows unauthenticated attackers to escalate privileges via network access. This aff...

Aug 8, 2023
CVE-2022-31576
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the heidi-luong1109/shackerpanel reposito...

Jul 11, 2022
CVE-2022-31579
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the ralphjzhang/iasset repository. It aff...

Jul 11, 2022
CVE-2022-31581
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the OpenMF application. It affects any de...

Jul 11, 2022
CVE-2022-31583
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the AutomatedQuizEval repository. It affe...

Jul 11, 2022
CVE-2022-31585
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the umeshpatil-dev/Home__internet repository, enabling unauthorized ...

Jul 11, 2022
CVE-2022-31587
9.3

This vulnerability allows attackers to perform absolute path traversal attacks by exploiting unsafe usage of Flask's send_file function in the yuriyou...

Jul 11, 2022
CVE-2022-31551
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the pleomax00/flask-mongo-skel repository, enabling unauthorized fil...

Jul 11, 2022
CVE-2022-31553
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the rainsoupah/sleep-learner GitHub repos...

Jul 11, 2022
CVE-2022-31555
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the romain20100/nursequest repository. It...

Jul 11, 2022
CVE-2022-31557
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the seveas/golem repository, enabling unauthorized file access. It a...

Jul 11, 2022
CVE-2022-31559
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the tsileo/flask-yeoman repository, enabling unauthorized file acces...

Jul 11, 2022
CVE-2022-31561
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the varijkapil13/Sphere_ImageBackend repository, enabling unauthoriz...

Jul 11, 2022
CVE-2022-31563
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the whmacmac/vprj GitHub repository, enabling unauthorized file acce...

Jul 11, 2022
CVE-2022-31565
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the yogson/syrabond repository. It affect...

Jul 11, 2022
CVE-2022-31567
9.3

This vulnerability allows attackers to read arbitrary files on the server through path traversal in the DSABenchmark/DSAB repository. It affects users...

Jul 11, 2022
CVE-2022-31572
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the ceee-vip/cockybook repository, enabling unauthorized file access...

Jul 11, 2022
CVE-2022-31574
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the deepaliupadhyay/RealEstate repository due to unsafe use of Flask...

Jul 11, 2022
CVE-2022-31535
9.3

This vulnerability allows attackers to read arbitrary files on the server by exploiting path traversal in the Fishtank repository's Flask application....

Jul 11, 2022
CVE-2022-31537
9.3

This vulnerability allows attackers to read arbitrary files on the server by exploiting path traversal in the Flask send_file function. It affects any...

Jul 11, 2022
CVE-2022-31539
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the kotekan/kotekan repository, enabling unauthorized file access. I...

Jul 11, 2022
CVE-2022-31541
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the Barry Voice Assistant Flask applicati...

Jul 11, 2022
CVE-2022-31543
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the SetupBox repository. It affects any s...

Jul 11, 2022
CVE-2022-31545
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the ml-inory/ModelConverter repository. I...

Jul 11, 2022
CVE-2022-31547
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the noamezekiel/sphere repository. It aff...

Jul 11, 2022
CVE-2022-31549
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the olmax99/helm-flask-celery repository....

Jul 11, 2022
CVE-2022-31525
9.3

This vulnerability allows attackers to read arbitrary files on the server through absolute path traversal in the SummaLabs/DLS repository. It affects ...

Jul 11, 2022
CVE-2022-31527
9.3

This vulnerability allows attackers to perform absolute path traversal attacks in the Wildog/flask-file-server repository, enabling unauthorized file ...

Jul 11, 2022

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,982 CVEs classified as CWE-22, with 445 rated critical and 998 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.6.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free