CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,496 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 13 of 210
- CVE-2022-47027CRITICALCVSS 9.8EG 9.82023-04-14
Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.
- CVE-2023-1478CRITICALCVSS 9.8EG 9.82023-04-10
The Hummingbird WordPress plugin before 3.4.2 does not validate the generated file path for page cache files before writing them, leading to a path traversal vulnerability in the page cache module.
- CVE-2023-27603CRITICALCVSS 9.8EG 9.82023-04-10
In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis…
- CVE-2023-29478CRITICALCVSS 9.8EG 9.82023-04-07
BiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on the filesystem. This includes the Minecraft mods folder, which results in code execution.
- CVE-2020-19279CRITICALCVSS 9.8EG 9.82023-04-04
Directory Traversal vulnerability found in B3log Wide allows a an attacker to escalate privileges via symbolic links.
- CVE-2022-36981CRITICALCVSS 9.8EG 9.82023-03-29
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be b…
- CVE-2023-26802CRITICALCVSS 9.8EG 9.82023-03-26
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.
- CVE-2023-27855CRITICALCVSS 9.8EG 9.82023-03-22
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any dire…
- CVE-2023-28371CRITICALCVSS 9.8EG 9.82023-03-15
In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
- CVE-2021-33353CRITICALCVSS 9.8EG 9.82023-03-08
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
- CVE-2023-22336CRITICALCVSS 9.8EG 9.82023-03-06
Path traversal vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attacker to upload a specially crafted file to an arbitrary directory. As a result of exploiting this vulnerabi…
- CVE-2023-0947CRITICALCVSS 9.8EG 9.82023-02-22
Path Traversal in GitHub repository flatpressblog/flatpress prior to 1.3.
- CVE-2022-48323CRITICALCVSS 9.8EG 9.82023-02-13
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP reques…
- CVE-2021-36471CRITICALCVSS 9.8EG 9.82023-02-07
Directory Traversal vulnerability in AdminLTE 3.1.0 allows remote attackers to gain escalated privilege and view sensitive information via /admin/index2.html, /admin/index3.html URIs. Note: AdminLTE developers dispute that this a weakness …
- CVE-2022-31706CRITICALCVSS 9.8EG 9.82023-01-26
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
- CVE-2022-45299CRITICALCVSS 9.8EG 9.82023-01-13
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.
- CVE-2022-48253CRITICALCVSS 9.8EG 9.82023-01-11
nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.
- CVE-2022-4298CRITICALCVSS 9.8EG 9.82023-01-02
The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
- CVE-2022-47945CRITICALCVSS 9.8EG 9.82022-12-23
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating sys…
- CVE-2022-3184CRITICALCVSS 9.8EG 9.82022-12-21
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where the device’s existing firmware allows unauthenticated users to access an old PHP page vulnerable to directory traversal, which may allow a user to writ…
- CVE-2022-4063CRITICALCVSS 9.8EG 9.82022-12-19
The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.
- CVE-2022-45969CRITICALCVSS 9.8EG 9.82022-12-15
Alist v3.4.0 is vulnerable to Directory Traversal,
- CVE-2022-46255CRITICALCVSS 9.8EG 9.82022-12-14
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the working directory is clean before unpa…
- CVE-2022-38165CRITICALCVSS 9.8EG 9.82022-11-17
Arbitrary file write in F-Secure Policy Manager through 2022-08-10 allows unauthenticated users to write the file with the contents in arbitrary locations on the F-Secure Policy Manager Server.
- CVE-2022-44006CRITICALCVSS 9.8EG 9.82022-11-16
An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. …
- CVE-2022-34822CRITICALCVSS 9.8EG 9.82022-11-08
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlie…
- CVE-2022-41772CRITICALCVSS 9.8EG 9.82022-10-31
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior mishandle .ZIP archives containing characters used in path traversal. This path traversal could result in remote code execution.
- CVE-2022-41657CRITICALCVSS 9.8EG 9.82022-10-31
Delta Electronics InfraSuite Device Master Versions 00.00.01a and prior allow attacker provided data already serialized into memory to be used in file operation application programmable interfaces (APIs). This could create arbitrary files…
- CVE-2022-39345CRITICALCVSS 9.8EG 9.82022-10-25
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.…
- CVE-2022-22128CRITICALCVSS 9.8EG 9.82022-10-17
Tableau discovered a path traversal vulnerability affecting Tableau Server Administration Agent’s internal file transfer service that could allow remote code execution.Tableau only supports product versions for 24 months after release. O…
- CVE-2022-38418CRITICALCVSS 9.8EG 9.82022-10-14
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in t…
- CVE-2022-28814CRITICALCVSS 9.8EG 9.82022-09-28
Carlo Gavazzi UWP3.0 in multiple versions and CPY Car Park Server in Version 2.8.3 was discovered to be vulnerable to a relative path traversal vulnerability which enables remote attackers to read arbitrary files and gain full control of t…
- CVE-2022-39033CRITICALCVSS 9.8EG 9.82022-09-28
Smart eVision’s file acquisition function has a path traversal vulnerability due to insufficient filtering for special characters in the URL parameter. An unauthenticated remote attacker can exploit this vulnerability to bypass authentic…
- CVE-2022-25371CRITICALCVSS 9.8EG 9.82022-09-02
Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a r…
- CVE-2020-21642CRITICALCVSS 9.8EG 9.82022-08-15
Directory Traversal vulnerability ZDBQAREFSUBDIR parameter in /zropusermgmt API in Zoho ManageEngine Analytics Plus before 4350 allows remote attackers to run arbitrary code.
- CVE-2022-38129CRITICALCVSS 9.8EG 9.82022-08-10
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to…
- CVE-2022-32409CRITICALCVSS 9.8EG 9.82022-07-14
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
- CVE-2022-31570CRITICALCVSS 9.8EG 9.82022-07-11
The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- CVE-2022-25046CRITICALCVSS 9.8EG 9.82022-07-07
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request.
- CVE-2022-31836CRITICALCVSS 9.8EG 9.82022-07-05
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
- CVE-2022-29774CRITICALCVSS 9.8EG 9.82022-06-21
iSpy v7.2.2.0 is vulnerable to remote command execution via path traversal.
- CVE-2022-32270CRITICALCVSS 9.8EG 9.82022-06-03
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (…
- CVE-2022-28945CRITICALCVSS 9.8EG 9.82022-06-02
An issue in Webbank WeCube v3.2.2 allows attackers to execute a directory traversal via a crafted ZIP file.
- CVE-2022-1664CRITICALCVSS 9.8EG 9.82022-05-26
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package for…
- CVE-2022-29596CRITICALCVSS 9.8EG 9.82022-05-11
MicroStrategy Enterprise Manager 2022 allows authentication bypass by triggering a login failure and then entering the Uid=/../../../../../../../../../../../windows/win.ini%00.jpg&Pwd=_any_password_&ConnMode=1&3054=Login substring for dire…
- CVE-2022-29081CRITICALCVSS 9.8EG 9.82022-04-28
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360 before 5401 are vulnerable to access-control bypass on a few Rest API URLs (for SSOutAction. SSLAction. LicenseMgr. GetProductDetails. GetDash…
- CVE-2022-29806CRITICALCVSS 9.8EG 9.82022-04-26
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
- CVE-2022-1391CRITICALCVSS 9.8EG 9.82022-04-25
The Cab fare calculator WordPress plugin before 1.0.4 does not validate the controller parameter before using it in require statements, which could lead to Local File Inclusion issues.
- CVE-2022-1390CRITICALCVSS 9.8EG 9.82022-04-25
The Admin Word Count Column WordPress plugin through 2.2 does not validate the path parameter given to readfile(), which could allow unauthenticated attackers to read arbitrary files on server running old version of PHP susceptible to the …
- CVE-2021-43290CRITICALCVSS 9.8EG 9.82022-04-14
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a malicious file into a directory of a GoCD server. They can control the filename but the directory is placed inside of a d…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →