CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 1 of 210
- CVE-2026-85706CRITICALCVSS 10.0EG 10.0⚠ KEV2026-09-12
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user cou…
- CVE-2026-48282CRITICALCVSS 10.0EG 10.0⚠ KEV2026-06-30
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user.…
- CVE-2026-34909CRITICALCVSS 10.0EG 10.0⚠ KEV2026-05-22
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying system that could be manipulated to access an underlying account.
- CVE-2025-34028CRITICALCVSS 10.0EG 10.0⚠ KEV2025-04-22
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in…
- CVE-2019-11510CRITICALCVSS 10.0EG 10.0⚠ KEV2019-05-08
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .
- CVE-2021-38163CRITICALCVSS 9.9EG 9.9⚠ KEV2021-09-14
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable o…
- CVE-2026-104286CRITICALCVSS 9.8EG 9.8⚠ KEV2026-10-01
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allo…
- CVE-2026-93616CRITICALCVSS 9.8EG 9.8⚠ KEV2026-09-22
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
- CVE-2026-59310CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-30
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.
- CVE-2025-61882CRITICALCVSS 9.8EG 9.8⚠ KEV2025-10-05
Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated a…
- CVE-2025-4632CRITICALCVSS 9.8EG 9.8⚠ KEV2025-05-13
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.
- CVE-2024-11667CRITICALCVSS 9.8EG 9.8⚠ KEV2024-11-27
A directory traversal vulnerability in the web management interface of Zyxel ATP series firmware versions V5.00 through V5.38, USG FLEX series firmware versions V5.00 through V5.38, USG FLEX 50(W) series firmware versions V5.10 through …
- CVE-2024-7399CRITICALCVSS 9.8EG 9.8⚠ KEV2024-08-12
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attackers to write arbitrary file as system authority.
- CVE-2024-4885CRITICALCVSS 9.8EG 9.8⚠ KEV2024-06-25
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The WhatsUp.ExportUtilities.Export.GetFileWithoutZip allows execution of commands with iisapppool\…
- CVE-2024-32113CRITICALCVSS 9.8EG 9.8⚠ KEV2024-05-08
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before 18.12.13. Users are recommended to upgrade to version 18.12.13, which fixes the issue.
- CVE-2024-23897CRITICALCVSS 9.8EG 9.8⚠ KEV2024-01-24
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a file path in an argument with the file's contents, allowing unauthenticated attackers to r…
- CVE-2023-47246CRITICALCVSS 9.8EG 9.8⚠ KEV2023-11-10
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat webroot, as exploited in the wild in November 2023.
- CVE-2022-41352CRITICALCVSS 9.8EG 9.8⚠ KEV2022-09-26
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to an…
- CVE-2022-37042CRITICALCVSS 9.8EG 9.8⚠ KEV2022-08-12
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the…
- CVE-2022-26352CRITICALCVSS 9.8EG 9.8⚠ KEV2022-07-17
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is sa…
- CVE-2022-29464CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-18
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such a…
- CVE-2021-42013CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-07
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of…
- CVE-2021-41773CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-05
A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these…
- CVE-2021-22005CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-23
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to execute code on vCenter Server by uploading a specia…
- CVE-2021-20090CRITICALCVSS 9.8EG 9.8⚠ KEV2021-04-29
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
- CVE-2021-21972CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-24
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor with network access to port 443 may exploit this issue to execute commands with unrestricted privileges on the underlyi…
- CVE-2021-3199CRITICALCVSS 9.8EG 9.8⚠ KEV2021-01-26
Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT is used, via a /.. sequence in an image upload parameter.
- CVE-2020-5902CRITICALCVSS 9.8EG 9.8⚠ KEV2020-07-01
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vuln…
- CVE-2019-19781CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-27
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. They allow Directory Traversal.
- CVE-2019-7195CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-05
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- CVE-2019-7194CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-05
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
- CVE-2019-16278CRITICALCVSS 9.8EG 9.8⚠ KEV2019-10-14
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
- CVE-2019-3396CRITICALCVSS 9.8EG 9.8⚠ KEV2019-03-25
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 before 6.13.3 (the fixed version for 6.13.x…
- CVE-2014-0780CRITICALCVSS 9.8EG 9.8⚠ KEV2014-04-25
Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.
- CVE-2010-2861CRITICALCVSS 9.8EG 9.8⚠ KEV2010-08-11
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) l…
- CVE-2018-13379CRITICALCVSS 9.1EG 9.8⚠ KEV2019-06-04
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web…
- CVE-2020-1631CRITICALCVSS 8.8EG 9.8⚠ KEV2020-05-04
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an unauthenticated attacker to perform local …
- CVE-2025-27920CRITICALCVSS 7.2EG 9.8⚠ KEV2025-05-05
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially lea…
- CVE-2024-8963CRITICALCVSS 9.4EG 9.4⚠ KEV2024-09-19
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
- CVE-2024-41713CRITICALCVSS 9.1EG 9.1⚠ KEV2024-10-21
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A successf…
- CVE-2018-14847CRITICALCVSS 9.1EG 9.1⚠ KEV2018-08-02
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
- CVE-2015-4068CRITICALCVSS 9.1EG 9.1⚠ KEV2015-05-29
Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.
- CVE-2025-8110CRITICALCVSS 8.8EG 9.0⚠ KEV2025-12-10
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
- CVE-2022-26500CRITICALCVSS 8.8EG 9.0⚠ KEV2022-03-17
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
- CVE-2019-3398CRITICALCVSS 8.8EG 9.0⚠ KEV2019-04-18
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote attacker who has permission to add attachments to pages and / or blogs or to create a new space or a personal space or wh…
- CVE-2018-5430CRITICALCVSS 8.8EG 9.0⚠ KEV2018-04-17
The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Repo…
- CVE-2024-28995CRITICALCVSS 8.6EG 9.0⚠ KEV2024-06-06
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
- CVE-2023-32315CRITICALCVSS 8.6EG 9.0⚠ KEV2023-05-26
Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauth…
- CVE-2024-1708CRITICALCVSS 8.4EG 9.0⚠ KEV2024-02-21
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.
- CVE-2025-6218CRITICALCVSS 7.8EG 9.0⚠ KEV2025-06-21
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerabil…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →