CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,496 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 14 of 210
- CVE-2021-43741CRITICALCVSS 9.8EG 9.82022-04-13
CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicious file on config.php leading to remote code execution.
- CVE-2022-25347CRITICALCVSS 9.8EG 9.82022-03-29
Delta Electronics DIAEnergie (All versions prior to 1.8.02.004) is vulnerable to path traversal attacks, which may allow an attacker to write arbitrary files to locations on the file system.
- CVE-2022-0679CRITICALCVSS 9.8EG 9.82022-03-28
The Narnoo Distributor WordPress plugin through 2.5.1 fails to validate and sanitize the lib_path parameter before it is passed into a call to require() via the narnoo_distributor_lib_request AJAX action (available to both unauthenticated …
- CVE-2021-45967CRITICALCVSS 9.8EG 9.82022-03-18
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
- CVE-2022-1000CRITICALCVSS 9.8EG 9.82022-03-17
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
- CVE-2021-45887CRITICALCVSS 9.8EG 9.82022-03-13
An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executable script can be uploaded by web application administrators, giving the attacker remote c…
- CVE-2021-42854CRITICALCVSS 9.8EG 9.82022-03-10
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent's (DSA) PluginServlet has directory traversal vulnerabilities at the "/api/appInternals/1.0/plugin/pmx" API. The affected endpoint does not have any input validati…
- CVE-2021-3762CRITICALCVSS 9.8EG 9.82022-03-03
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image which, when scanned by Clair, allows for arbitrary file write on the filesystem, potentiall…
- CVE-2022-24977CRITICALCVSS 9.8EG 9.82022-02-14
ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSI…
- CVE-2022-24312CRITICALCVSS 9.8EG 9.82022-02-09
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leadin…
- CVE-2022-24311CRITICALCVSS 9.8EG 9.82022-02-09
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potential…
- CVE-2022-0401CRITICALCVSS 9.8EG 9.82022-02-01
Path Traversal in NPM w-zip prior to 1.0.12.
- CVE-2022-0320CRITICALCVSS 9.8EG 9.82022-02-01
The Essential Addons for Elementor WordPress plugin before 5.0.5 does not validate and sanitise some template data before it them in include statements, which could allow unauthenticated attackers to perform Local File Inclusion attack and…
- CVE-2021-23484CRITICALCVSS 9.8EG 9.82022-01-28
The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.
- CVE-2020-17383CRITICALCVSS 9.8EG 9.82022-01-24
A directory traversal vulnerability on Telos Z/IP One devices through 4.0.0r grants an unauthenticated individual root level access to the device's file system. This can be used to identify configuration settings, password hashes for built…
- CVE-2021-37128CRITICALCVSS 9.8EG 9.82022-01-03
HwPCAssistant has a Path Traversal vulnerability .Successful exploitation of this vulnerability may write any file.
- CVE-2021-45427CRITICALCVSS 9.8EG 9.82021-12-30
Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.
- CVE-2021-44548CRITICALCVSS 9.8EG 9.82021-12-23
An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows UNC path resulting in an SMB network call being made from the Solr host to another host on the network. If the attacker …
- CVE-2021-31746CRITICALCVSS 9.8EG 9.82021-12-10
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution.
- CVE-2021-43676CRITICALCVSS 9.8EG 9.82021-12-03
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
- CVE-2021-44278CRITICALCVSS 9.8EG 9.82021-12-03
Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
- CVE-2021-43674CRITICALCVSS 9.8EG 9.82021-12-03
ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2021-43691CRITICALCVSS 9.8EG 9.82021-11-29
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.
- CVE-2021-21692CRITICALCVSS 9.8EG 9.82021-11-04
FilePath#renameTo and FilePath#moveAllChildrenTo in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier only check 'read' agent-to-controller access permission on the source path, instead of 'delete'.
- CVE-2021-21690CRITICALCVSS 9.8EG 9.82021-11-04
Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path in Jenkins 2.318 and earlier, LTS 2.303.2 and earlier.
- CVE-2021-29212CRITICALCVSS 9.8EG 9.82021-11-01
A remote unauthenticated directory traversal security vulnerability has been identified in HPE iLO Amplifier Pack versions 1.80, 1.81, 1.90 and 1.95. The vulnerability could be remotely exploited to allow an unauthenticated user to run arb…
- CVE-2021-40371CRITICALCVSS 9.8EG 9.82021-10-25
Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, as demonstrated by ..\\ in a scriptName JSON value to ServiceManagerTenant/GetVisibilityMap.
- CVE-2020-27304CRITICALCVSS 9.8EG 9.82021-10-21
The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file u…
- CVE-2021-20125CRITICALCVSS 9.8EG 9.82021-10-13
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files t…
- CVE-2021-40887CRITICALCVSS 9.8EG 9.82021-10-11
Projectsend version r1295 is affected by a directory traversal vulnerability. Because of lacking sanitization input for files[] parameter, an attacker can add ../ to move all PHP files or any file on the system that has permissions to /upl…
- CVE-2021-40960CRITICALCVSS 9.8EG 9.82021-10-01
Galera WebTemplate 1.0 is affected by a directory traversal vulnerability that could reveal information from /etc/passwd and /etc/shadow.
- CVE-2021-41290CRITICALCVSS 9.8EG 9.82021-09-30
ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, unauthenticated attackers can remotely set arbitrary values for location and content type and gain the possibility to exe…
- CVE-2021-40098CRITICALCVSS 9.8EG 9.82021-09-27
An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regular expression.
- CVE-2021-27341CRITICALCVSS 9.8EG 9.82021-09-16
OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via the "filename" parameter.
- CVE-2020-21125CRITICALCVSS 9.8EG 9.82021-09-15
An arbitrary file creation vulnerability in UReport 2.2.9 allows attackers to execute arbitrary code.
- CVE-2021-34436CRITICALCVSS 9.8EG 9.82021-09-02
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language supp…
- CVE-2021-38197CRITICALCVSS 9.8EG 9.82021-08-08
unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR archive.
- CVE-2020-19305CRITICALCVSS 9.8EG 9.82021-08-03
An issue in /app/system/column/admin/index.class.php of Metinfo v7.0.0 causes the indeximg parameter to be deleted when the column is deleted, allowing attackers to escalate privileges.
- CVE-2021-24375CRITICALCVSS 9.8EG 9.82021-07-06
Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary …
- CVE-2021-31272CRITICALCVSS 9.8EG 9.82021-06-18
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.
- CVE-2021-33576CRITICALCVSS 9.8EG 9.82021-06-18
An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filename can include path-traversal characters, allowing the file to be written to an arbitrary location on disk.
- CVE-2021-32682CRITICALCVSS 9.8EG 9.82021-06-14
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hostin…
- CVE-2020-18178CRITICALCVSS 9.8EG 9.82021-05-18
Path Traversal in HongCMS v4.0.0 allows remote attackers to view, edit, and delete arbitrary files via a crafted POST request to the component "/hcms/admin/index.php/language/ajax."
- CVE-2021-31800CRITICALCVSS 9.8EG 9.82021-05-05
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially b…
- CVE-2021-28959CRITICALCVSS 9.8EG 9.82021-04-30
Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a ZIP archive. This leads to remote code execution.
- CVE-2021-26714CRITICALCVSS 9.8EG 9.82021-03-29
The Enterprise License Manager portal in Mitel MiContact Center Enterprise before 9.4 could allow a user to access restricted files and folders due to insufficient access control. A successful exploit could allow an attacker to view and mo…
- CVE-2021-29417CRITICALCVSS 9.8EG 9.82021-03-29
gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal.
- CVE-2021-26293CRITICALCVSS 9.8EG 9.82021-03-04
An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer…
- CVE-2021-25833CRITICALCVSS 9.8EG 9.82021-03-01
A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file extension is controlled by an attacker through the request data and leads to arbitrary file overwriting. Using this vul…
- CVE-2021-25140CRITICALCVSS 9.8EG 9.82021-02-09
A potential security vulnerability has been identified in the HPE Moonshot Provisioning Manager v1.20. The HPE Moonshot Provisioning Manager is an application that is installed in a VMWare or Microsoft Hyper-V environment that is used to s…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →