CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,495 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 12 of 210
- CVE-2023-6559CRITICALCVSS 9.8EG 9.82023-12-16
The MW WP Form plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 5.0.3. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it po…
- CVE-2023-6458CRITICALCVSS 9.8EG 9.82023-12-06
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traversal.
- CVE-2023-3533CRITICALCVSS 9.8EG 9.82023-11-28
Path traversal in file upload functionality in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via a…
- CVE-2023-42000CRITICALCVSS 9.8EG 9.82023-11-27
Arcserve UDP prior to 9.2 contains a path traversal vulnerability in com.ca.arcflash.ui.server.servlet.FileHandlingServlet.doUpload(). An unauthenticated remote attacker can exploit it to upload arbitrary files to any location on the file …
- CVE-2023-6307CRITICALCVSS 9.8EG 9.82023-11-27
A vulnerability classified as critical was found in jeecgboot JimuReport up to 1.6.1. Affected by this vulnerability is an unknown functionality of the file /download/image. The manipulation of the argument imageUrl leads to relative path …
- CVE-2023-5245CRITICALCVSS 9.8EG 9.82023-11-15
FileUtil.extract() enumerates all zip file entries and extracts each file without validating whether file paths in the archive are outside the intended directory. When creating an instance of TensorflowModel using the saved_model format a…
- CVE-2023-30967CRITICALCVSS 9.8EG 9.82023-10-26
Gotham Orbital-Simulator service prior to 0.692.0 was found to be vulnerable to a Path traversal issue allowing an unauthenticated user to read arbitrary files on the file system.
- CVE-2023-39332CRITICALCVSS 9.8EG 9.82023-10-18
Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Array` class. Node.js prevents path traversal through strings (see CVE-2023-30584) …
- CVE-2023-5399CRITICALCVSS 9.8EG 9.82023-10-04
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause tampering of files on the personal computer running C-Bus when using the File Command.
- CVE-2023-44172CRITICALCVSS 9.8EG 9.82023-09-27
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_weixin.php.
- CVE-2023-44171CRITICALCVSS 9.8EG 9.82023-09-27
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_smtp.php.
- CVE-2023-44170CRITICALCVSS 9.8EG 9.82023-09-27
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ping.php.
- CVE-2023-44169CRITICALCVSS 9.8EG 9.82023-09-27
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_notify.php.
- CVE-2023-43216CRITICALCVSS 9.8EG 9.82023-09-27
SeaCMS V12.9 was discovered to contain an arbitrary file write vulnerability via the component admin_ip.php.
- CVE-2023-4760CRITICALCVSS 9.8EG 9.82023-09-21
In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUp…
- CVE-2015-5467CRITICALCVSS 9.8EG 9.82023-09-21
web\ViewAction in Yii (aka Yii2) 2.x before 2.0.5 allows attackers to execute any local .php file via a relative path in the view parameeter.
- CVE-2022-28357CRITICALCVSS 9.8EG 9.82023-09-19
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
- CVE-2023-4614CRITICALCVSS 9.8EG 9.82023-09-04
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThum…
- CVE-2023-4613CRITICALCVSS 9.8EG 9.82023-09-04
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endp…
- CVE-2023-39699CRITICALCVSS 9.8EG 9.82023-08-25
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of…
- CVE-2023-26469CRITICALCVSS 9.8EG 9.82023-08-17
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
- CVE-2023-2917CRITICALCVSS 9.8EG 9.82023-08-17
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes…
- CVE-2020-26037CRITICALCVSS 9.8EG 9.82023-08-16
Directory Traversal vulnerability in Server functionalty in Even Balance Punkbuster version 1.902 before 1.905 allows remote attackers to execute arbitrary code.
- CVE-2023-32563CRITICALCVSS 9.8EG 9.82023-08-10
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
- CVE-2023-39143CRITICALCVSS 9.8EG 9.82023-08-04
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common config…
- CVE-2023-38951CRITICALCVSS 9.8EG 9.82023-08-03
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in th…
- CVE-2022-46898CRITICALCVSS 9.8EG 9.82023-07-25
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is Path Traversal via the "restore SQL data" filename. The Vocera Report Console contains a websocket function that allows for the restoration of the d…
- CVE-2023-34478CRITICALCVSS 9.8EG 9.82023-07-24
Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.…
- CVE-2023-26564CRITICALCVSS 9.8EG 9.82023-07-12
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any …
- CVE-2023-26563CRITICALCVSS 9.8EG 9.82023-07-12
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any fi…
- CVE-2023-34598CRITICALCVSS 9.8EG 9.82023-06-29
Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI) where it's possible to include the content of several files present in the installation folder in the server's response.
- CVE-2020-19902CRITICALCVSS 9.8EG 9.82023-06-27
Directory Traversal vulnerability found in Cryptoprof WCMS v.0.3.2 allows a remote attacker to execute arbitrary code via the wex/cssjs.php parameter.
- CVE-2023-30945CRITICALCVSS 9.8EG 9.82023-06-26
Multiple Services such as VHS(Video History Server) and VCD(Video Clip Distributor) and Clips2 were discovered to be vulnerable to an unauthenticated arbitrary file read/write vulnerability due to missing input validation on filenames. A m…
- CVE-2023-32557CRITICALCVSS 9.8EG 9.82023-06-26
A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privile…
- CVE-2023-34939CRITICALCVSS 9.8EG 9.82023-06-22
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
- CVE-2023-34880CRITICALCVSS 9.8EG 9.82023-06-15
cmseasy v7.7.7.7 20230520 was discovered to contain a path traversal vulnerability via the add_action method at lib/admin/language_admin.php. This vulnerability allows attackers to execute arbitrary code and perform a local file inclusion.
- CVE-2023-34865CRITICALCVSS 9.8EG 9.82023-06-14
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
- CVE-2023-2278CRITICALCVSS 9.8EG 9.82023-06-13
The WP Directory Kit plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.1.9 via the 'wdk_public_action' function. This allows unauthenticated attackers to include and execute arbitrary files on t…
- CVE-2023-34409CRITICALCVSS 9.8EG 9.82023-06-06
In Percona Monitoring and Management (PMM) server 2.x before 2.37.1, the authenticate function in auth_server.go does not properly formalize and sanitize URL paths to reject path traversal attempts. This allows an unauthenticated remote us…
- CVE-2023-29736CRITICALCVSS 9.8EG 9.82023-06-01
Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary files in its internal storage and achieve arbitrary code execution.
- CVE-2022-47526CRITICALCVSS 9.8EG 9.82023-05-31
Fox-IT DataDiode (aka Fox DataDiode) 3.4.3 suffers from a path traversal vulnerability with resultant arbitrary writing of files. A remote attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the…
- CVE-2022-24629CRITICALCVSS 9.8EG 9.82023-05-29
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can u…
- CVE-2023-28413CRITICALCVSS 9.8EG 9.82023-05-23
Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition.
- CVE-2023-28408CRITICALCVSS 9.8EG 9.82023-05-23
Directory traversal vulnerability in MW WP Form versions v4.4.2 and earlier allows a remote unauthenticated attacker to alter the website or cause a denial-of-service (DoS) condition, and obtain sensitive information depending on settings.
- CVE-2023-27507CRITICALCVSS 9.8EG 9.82023-05-23
MicroEngine Mailform version 1.1.0 to 1.1.8 contains a path traversal vulnerability. If the product's file upload function and server save option are enabled, a remote attacker may save an arbitrary file on the server and execute it.
- CVE-2020-20012CRITICALCVSS 9.8EG 9.82023-05-23
WebPlus Pro v1.4.7.8.4-01 is vulnerable to Incorrect Access Control.
- CVE-2023-30268CRITICALCVSS 9.8EG 9.82023-05-04
CLTPHP <=6.0 is vulnerable to Improper Input Validation.
- CVE-2022-47757CRITICALCVSS 9.8EG 9.82023-05-04
In imo.im 2022.11.1051, a path traversal vulnerability delivered via an unsanitized deeplink can force the application to write a file into the application's data directory. This may allow an attacker to save a shared library under a speci…
- CVE-2023-27105CRITICALCVSS 9.8EG 9.82023-04-25
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modif…
- CVE-2023-27648CRITICALCVSS 9.8EG 9.82023-04-14
Directory Traversal vulnerability found in T-ME Studios Change Color of Keypad v.1.275.1.277 allows a remote attacker to execute arbitrary code via the dex file in the internal storage.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →