CWE-22: Path Traversal

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

1,995
Total CVEs
447
Critical
1,009
High
7.7
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
231
2025
685
2024
481
2023
231
2022
165

Top Affected Vendors

1 Apple 26
2 Qnap 21
3 Ivanti 18
4 Fortinet 16
5 Samsung 16
6 Solarwinds 16
7 Fedoraproject 16
8 Siemens 15
9 Adobe 15
10 Debian 13

All Path Traversal CVEs (1,995)

CVE-2022-24840
9.1

CVE-2022-24840 is a path traversal vulnerability in django-s3file that allows attackers to access or delete files across an entire AWS S3 bucket. All ...

Jun 9, 2022
CVE-2022-31483
9.1

This is a path traversal vulnerability in HID Mercury Intelligent Controllers that allows authenticated attackers to upload files anywhere on the file...

Jun 6, 2022
CVE-2022-25591
9.1

CVE-2022-25591 is an arbitrary file deletion vulnerability in BlogEngine.NET that allows attackers to delete files within the web server root director...

May 13, 2022
CVE-2021-22794
9.1

This path traversal vulnerability in StruxureWare Data Center Expert allows attackers to access files outside the intended directory, potentially lead...

Apr 13, 2022
CVE-2022-26960
9.1

CVE-2022-26960 is a path traversal vulnerability in elFinder's connector.minimal.php that allows unauthenticated attackers to read, write, and browse ...

Mar 21, 2022
CVE-2022-23357
9.1

CVE-2022-23357 is a directory traversal vulnerability in mozilo2.0 CMS that allows attackers to access arbitrary files on the server via the 'curent_d...

Feb 3, 2022
CVE-2021-40525
9.1

CVE-2021-40525 is a path traversal vulnerability in Apache James ManagedSieve implementation that allows attackers to read and write arbitrary files o...

Jan 4, 2022
CVE-2020-20944
9.1

This vulnerability in Qibosoft v7 allows attackers to delete arbitrary files via the /admin/index.php endpoint with specific parameters. Attackers can...

Dec 27, 2021
CVE-2021-21894
9.1

This CVE describes an authenticated directory traversal vulnerability in Lantronix PremierWave 2050's Web Manager FsTFtp functionality. An attacker wi...

Dec 22, 2021
CVE-2021-45015
9.1

CVE-2021-45015 is an arbitrary file deletion vulnerability in TaoCMS that allows attackers to delete any file on the server. This affects TaoCMS 3.0.2...

Dec 14, 2021
CVE-2021-37087
9.1

This CVE describes a path traversal vulnerability in Huawei smartphones running HarmonyOS that allows attackers to create arbitrary files. Successful ...

Dec 7, 2021
CVE-2021-37099
9.1

This path traversal vulnerability in Huawei smartphones allows attackers to delete arbitrary files on affected devices. The vulnerability affects Huaw...

Dec 7, 2021
CVE-2021-37064
9.1

This vulnerability allows attackers to create arbitrary files on Huawei smartphones by exploiting improper pathname restrictions. It affects Huawei de...

Dec 7, 2021
CVE-2021-43778
9.1

This CVE describes a path traversal vulnerability in the Barcode plugin for GLPI that allows attackers to read arbitrary files on the server. It affec...

Nov 24, 2021
CVE-2021-33724
9.1

CVE-2021-33724 is an arbitrary file deletion vulnerability in Siemens SINEC NMS that allows attackers to delete files or directories at user-controlle...

Oct 12, 2021
CVE-2021-41294
9.1

ECOA BAS controller has an unauthenticated path traversal vulnerability that allows remote attackers to delete arbitrary files via a specific GET para...

Sep 30, 2021
CVE-2021-24638
9.1

The OMGF WordPress plugin before version 4.5.4 has an unauthenticated path traversal vulnerability in its REST API. This allows attackers to overwrite...

Sep 20, 2021
CVE-2021-22704
9.1

This vulnerability allows attackers to exploit a path traversal flaw in Schneider Electric's Harmony HMI products when accessed via FTP. Attackers cou...

Sep 2, 2021
CVE-2021-35958
9.1

This vulnerability in TensorFlow allows attackers to overwrite arbitrary files on the system when tf.keras.utils.get_file is used with extract=True on...

Jun 30, 2021
CVE-2021-34363
9.1

CVE-2021-34363 is a path traversal vulnerability in thefuck Python package that allows attackers to delete arbitrary files via the 'undo archive opera...

Jun 10, 2021
CVE-2020-20907
9.1

MetInfo 7.0 beta contains a path traversal vulnerability that allows attackers to delete and modify critical INI configuration files. This affects all...

May 24, 2021
CVE-2021-21001
9.1

This vulnerability allows authenticated attackers with network access to WAGO PFC200 devices to access the file system with elevated privileges via sp...

May 24, 2021
CVE-2021-33497
9.1

This vulnerability allows attackers to delete arbitrary files on the server through directory traversal in the file deletion functionality of transfer...

May 24, 2021
CVE-2020-18070
9.1

This path traversal vulnerability in iCMS v7.0.13 allows remote attackers to delete arbitrary folders on the server by sending specially crafted HTTP ...

Apr 30, 2021
CVE-2020-17563
9.1

CVE-2020-17563 is a path traversal vulnerability in FeiFeiCMS v4.0 that allows remote attackers to delete arbitrary files on the server by sending a s...

Apr 22, 2021
CVE-2021-20078
9.1

CVE-2021-20078 is a path traversal vulnerability in ManageEngine OpManager's Spark Gateway component that allows remote attackers to delete arbitrary ...

Apr 1, 2021
CVE-2021-20651
9.1

This directory traversal vulnerability in ELECOM File Manager allows remote attackers to create or overwrite arbitrary files within directories access...

Feb 12, 2021
CVE-2020-15097
9.1

CVE-2020-15097 is a path traversal vulnerability in loklak server that allows attackers to read and write arbitrary files on the server filesystem. Th...

Feb 2, 2021
CVE-2020-35883
9.1

This vulnerability in the mozwire Rust crate allows attackers to perform directory traversal attacks, enabling them to overwrite local configuration f...

Dec 31, 2020
CVE-2020-26837
9.1

CVE-2020-26837 is a path traversal vulnerability in SAP Solution Manager 7.2's User Experience Monitoring component that allows authenticated users to...

Dec 9, 2020
CVE-2020-9920
9.1

This vulnerability allows a malicious mail server to overwrite arbitrary files on Apple devices through a path handling issue in mail processing. It a...

Oct 22, 2020
CVE-2020-18191
9.1

CVE-2020-18191 is a directory traversal vulnerability in GetSimpleCMS 3.3.15 that allows remote attackers to delete arbitrary files via the /admin/log...

Oct 2, 2020
CVE-2025-48017
9.0

This vulnerability allows attackers to modify and upload arbitrary files by exploiting improper pathname limitations in Circuit Provisioning and File ...

May 20, 2025
CVE-2025-27590
9.0

This vulnerability in oxidized-web allows unauthenticated attackers to execute arbitrary commands as the Linux user running the oxidized-web service. ...

Mar 3, 2025
CVE-2024-45593
9.0

This vulnerability in Nix package manager allows attackers to write arbitrary files to any location the Nix process can access. When the Nix daemon ru...

Sep 10, 2024
CVE-2024-7777
9.0

This vulnerability in the Bit Form WordPress plugin allows authenticated attackers with Administrator-level access to read and delete arbitrary files ...

Aug 20, 2024
CVE-2024-39619
9.0

This vulnerability allows unauthenticated attackers to perform local file inclusion (LFI) through path traversal in the ListingPro WordPress plugin. A...

Aug 1, 2024
CVE-2024-37089
9.0

This vulnerability allows unauthenticated attackers to perform path traversal attacks, leading to local file inclusion in the Consulting Elementor Wid...

Jun 24, 2024
CVE-2024-35677
9.0

This vulnerability allows unauthenticated attackers to perform path traversal attacks in the StylemixThemes MegaMenu WordPress plugin, leading to loca...

Jun 10, 2024
CVE-2024-34551
9.0

This vulnerability allows unauthenticated attackers to perform path traversal attacks in the Stockholm WordPress theme, leading to local file inclusio...

Jun 4, 2024
CVE-2024-33560
9.0

This vulnerability allows unauthenticated attackers to perform path traversal attacks in the XStore WordPress theme, leading to local file inclusion. ...

Jun 4, 2024
CVE-2024-32002
9.0

This CVE describes a vulnerability in Git where specially crafted repositories with submodules can trick Git into writing files into a .git/ directory...

May 14, 2024
CVE-2024-21400
9.0

This vulnerability allows an attacker with local access to a Microsoft Azure Kubernetes Service (AKS) confidential container to elevate privileges and...

Mar 12, 2024
CVE-2023-35169
9.0

CVE-2023-35169 is a critical directory traversal vulnerability in PHP-IMAP library that allows unauthenticated attackers to achieve remote code execut...

Jun 23, 2023
CVE-2023-21456
9.0

A path traversal vulnerability in Samsung Galaxy Themes Service allows attackers to access arbitrary files with system-level privileges. This affects ...

Mar 16, 2023
CVE-2020-29026
9.0

A directory traversal vulnerability in GateManager's file upload function allows authenticated administrators to read and write arbitrary files on the...

Feb 15, 2021
CVE-2020-13376
9.0

This vulnerability in SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files via a crafted cookie, leading to remote command executi...

Aug 7, 2020
CVE-2026-28676
8.8

OpenSift versions before 1.6.3-alpha contain a path traversal vulnerability (CWE-22) in multiple storage helpers that don't properly enforce directory...

Mar 6, 2026
CVE-2026-1311
8.8

The Worry Proof Backup WordPress plugin contains a path traversal vulnerability that allows authenticated attackers with Subscriber-level access or hi...

Feb 26, 2026
CVE-2026-27969
8.8

This CVE allows attackers with read/write access to Vitess backup storage locations to manipulate backup manifest files and perform path traversal att...

Feb 26, 2026

About Path Traversal (CWE-22)

The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences that can resolve to a location outside of that directory.

Our database tracks 1,995 CVEs classified as CWE-22, with 447 rated critical and 1,009 rated high severity. The average CVSS score for Path Traversal vulnerabilities is 7.7.

External reference: View CWE-22 on MITRE CWE →

Monitor Path Traversal Vulnerabilities

Get alerted when new Path Traversal CVEs affect your infrastructure.

Start Monitoring Free