CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 2 of 210
- CVE-2024-7262CRITICALCVSS 7.8EG 9.0⚠ KEV2024-08-15
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows allows an attacker to load an arbitrary Windows library. The vulnerability was found weaponi…
- CVE-2022-20775CRITICALCVSS 7.8EG 9.0⚠ KEV2022-09-30
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker coul…
- CVE-2022-21999CRITICALCVSS 7.8EG 9.0⚠ KEV2022-02-09
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2021-40444CRITICALCVSS 7.8EG 9.0⚠ KEV2021-09-15
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Of…
- CVE-2021-27065CRITICALCVSS 7.8EG 9.0⚠ KEV2021-03-03
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2018-20250CRITICALCVSS 7.8EG 9.0⚠ KEV2019-02-05
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extr…
- CVE-2015-0016CRITICALCVSS 7.8EG 9.0⚠ KEV2015-01-13
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 a…
- CVE-2025-61884CRITICALCVSS 7.5EG 9.0⚠ KEV2025-10-12
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network ac…
- CVE-2024-57727CRITICALCVSS 7.5EG 9.0⚠ KEV2025-01-15
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. Thes…
- CVE-2023-38950CRITICALCVSS 7.5EG 9.0⚠ KEV2023-08-03
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime.
- CVE-2022-30333CRITICALCVSS 7.5EG 9.0⚠ KEV2022-05-09
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
- CVE-2021-43798CRITICALCVSS 7.5EG 9.0⚠ KEV2021-12-07
Grafana is an open-source platform for monitoring and observability. Grafana versions 8.0.0-beta1 through 8.3.0 (except for patched versions) iss vulnerable to directory traversal, allowing access to local files. The vulnerable URL path is…
- CVE-2021-41277CRITICALCVSS 7.5EG 9.0⚠ KEV2021-11-17
Metabase is an open source data analytics platform. In affected versions a security issue has been discovered with the custom GeoJSON map (`admin->settings->maps->custom maps->add a map`) support and potential local file inclusion (includi…
- CVE-2021-20124CRITICALCVSS 7.5EG 9.0⚠ KEV2021-10-13
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the …
- CVE-2021-20123CRITICALCVSS 7.5EG 9.0⚠ KEV2021-10-13
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files …
- CVE-2020-36193CRITICALCVSS 7.5EG 9.0⚠ KEV2021-01-18
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
- CVE-2020-14864CRITICALCVSS 7.5EG 9.0⚠ KEV2020-10-21
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerabi…
- CVE-2020-3452CRITICALCVSS 7.5EG 9.0⚠ KEV2020-07-22
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks and …
- CVE-2020-5410CRITICALCVSS 7.5EG 9.0⚠ KEV2020-06-02
Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or…
- CVE-2020-11738CRITICALCVSS 7.5EG 9.0⚠ KEV2020-04-13
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
- CVE-2019-20085CRITICALCVSS 7.5EG 9.0⚠ KEV2019-12-30
TVT NVMS-1000 devices allow GET /.. Directory Traversal
- CVE-2019-7483CRITICALCVSS 7.5EG 9.0⚠ KEV2019-12-19
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
- CVE-2019-18187CRITICALCVSS 7.5EG 9.0⚠ KEV2019-10-28
Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could poten…
- CVE-2019-5418CRITICALCVSS 7.5EG 9.0⚠ KEV2019-03-27
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
- CVE-2018-0296CRITICALCVSS 7.5EG 9.0⚠ KEV2018-06-07
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. It is…
- CVE-2017-12637CRITICALCVSS 7.5EG 9.0⚠ KEV2017-08-07
Directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS in SAP NetWeaver Application Server Java 7.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the query string, as exploited in t…
- CVE-2016-3976CRITICALCVSS 7.5EG 9.0⚠ KEV2016-04-07
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.
- CVE-2016-0752CRITICALCVSS 7.5EG 9.0⚠ KEV2016-02-16
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an applica…
- CVE-2015-3035CRITICALCVSS 7.5EG 9.0⚠ KEV2015-04-22
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (…
- CVE-2015-0666CRITICALCVSS 7.5EG 9.0⚠ KEV2015-04-03
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.
- CVE-2024-27199CRITICALCVSS 7.3EG 9.0⚠ KEV2024-03-04
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
- CVE-2025-2749CRITICALCVSS 7.2EG 9.0⚠ KEV2025-03-24
An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content tha…
- CVE-2024-57728CRITICALCVSS 7.2EG 9.0⚠ KEV2025-01-15
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in t…
- CVE-2023-35081CRITICALCVSS 7.2EG 9.0⚠ KEV2023-08-03
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
- CVE-2022-27925CRITICALCVSS 7.2EG 9.0⚠ KEV2022-04-21
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, lea…
- CVE-2022-41328CRITICALCVSS 6.7EG 9.0⚠ KEV2023-03-07
A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write f…
- CVE-2021-31207CRITICALCVSS 6.6EG 9.0⚠ KEV2021-05-11
Microsoft Exchange Server Security Feature Bypass Vulnerability
- CVE-2018-2380CRITICALCVSS 6.6EG 9.0⚠ KEV2018-03-01
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
- CVE-2026-20262CRITICALCVSS 6.5EG 9.0⚠ KEV2026-06-15
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability ex…
- CVE-2023-41266CRITICALCVSS 6.5EG 9.0⚠ KEV2023-08-29
A path traversal vulnerability found in Qlik Sense Enterprise for Windows for versions May 2023 Patch 3 and earlier, February 2023 Patch 7 and earlier, November 2022 Patch 10 and earlier, and August 2022 Patch 12 and earlier allows an unau…
- CVE-2020-8195CRITICALCVSS 6.5EG 9.0⚠ KEV2020-07-10
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information d…
- CVE-2020-11652CRITICALCVSS 6.5EG 9.0⚠ KEV2020-04-30
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to auth…
- CVE-2018-18809CRITICALCVSS 6.5EG 9.0⚠ KEV2019-03-07
The default server implementation of TIBCO Software Inc.'s TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO JasperReports Server, TIBCO JasperReports Server…
- CVE-2013-3993CRITICALCVSS 6.5EG 9.0⚠ KEV2014-07-07
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file and directory restrictions, or access untrusted data or code, via crafted parameters in unspecified API calls.
- CVE-2026-66384CRITICALCVSS 5.3EG 9.0⚠ KEV2026-08-12
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
- CVE-2024-0769CRITICALCVSS 5.3EG 9.0⚠ KEV2024-01-21
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. Th…
- CVE-2021-26086CRITICALCVSS 5.3EG 9.0⚠ KEV2021-08-16
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8…
- CVE-2021-20023CRITICALCVSS 4.9EG 9.0⚠ KEV2021-04-20
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
- CVE-2020-4430CRITICALCVSS 4.3EG 9.0⚠ KEV2020-05-07
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM…
- CVE-2024-55550CRITICALCVSS 2.7EG 9.0⚠ KEV2024-12-10
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to a…
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →