CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,494 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 3 of 210
- CVE-2026-55393CRITICALCVSS 10.0EG 10.02026-10-01
Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and …
- CVE-2026-97163CRITICALCVSS 10.0EG 10.02026-09-26
Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29
- CVE-2026-80155CRITICALCVSS 10.0EG 10.02026-09-22
Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web managemen…
- CVE-2026-76606CRITICALCVSS 10.0EG 10.02026-08-22
Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.
- CVE-2026-18051CRITICALCVSS 10.0EG 10.02026-08-19
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outsid…
- CVE-2026-74764CRITICALCVSS 10.0EG 10.02026-08-15
Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor passed archive member names directly to Python's tarfile.TarFile.extract() without applying…
- CVE-2026-16940CRITICALCVSS 10.0EG 10.02026-08-05
The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php), which can lead to a full site take…
- CVE-2026-67429CRITICALCVSS 10.0EG 10.02026-07-29
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller-controlled output_dir instead of validate_path_with_env_config and its FLYTO_SANDBOX_DIR …
- CVE-2026-59555CRITICALCVSS 10.0EG 10.02026-07-23
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
- CVE-2026-15631CRITICALCVSS 10.0EG 10.02026-07-18
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves t…
- CVE-2026-58192CRITICALCVSS 10.0EG 10.02026-07-08
Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 1.1.6, the Appium storage plugin exposes POST /storage/delete, whose handler passes the user-supplied name value di…
- CVE-2026-54917CRITICALCVSS 10.0EG 10.02026-06-25
SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With …
- CVE-2026-48055CRITICALCVSS 10.0EG 10.02026-06-17
Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does …
- CVE-2026-48020CRITICALCVSS 10.0EG 10.02026-06-11
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authenticatio…
- CVE-2026-11429CRITICALCVSS 10.0EG 10.02026-06-05
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destination path without validation, allowing ar…
- CVE-2026-7411CRITICALCVSS 10.0EG 10.02026-05-05
In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal attack. By supplying a maliciously crafted …
- CVE-2026-36767CRITICALCVSS 10.0EG 10.02026-04-30
A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.
- CVE-2026-41211CRITICALCVSS 10.0EG 10.02026-04-23
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` string and uses it directly in filesystem paths. A caller can supply `../` segments or an …
- CVE-2026-39861CRITICALCVSS 10.0EG 10.02026-04-21
Claude Code is an agentic coding tool. Prior to version 2.1.64, Claude Code's sandbox did not prevent sandboxed processes from creating symlinks pointing to locations outside the workspace. When Claude Code subsequently wrote to a path wit…
- CVE-2025-15036CRITICALCVSS 10.0EG 10.02026-03-30
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlflow/mlflow repository. This vulnerability, present in versions before v3.7.0, arises due t…
- CVE-2026-22557CRITICALCVSS 10.0EG 10.02026-03-19
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on the underlying system that could be manipulated to access an underlying account.
- CVE-2026-2731CRITICALCVSS 10.0EG 10.02026-02-19
Path traversal and content injection in JobRunnerBackground.aspx in DynamicWeb 8 (all) and 9 (<9.19.7 and <9.20.3) allows unauthenticated attackers to execute code via simple web requests
- CVE-2025-69770CRITICALCVSS 10.0EG 10.02026-02-13
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
- CVE-2025-64075CRITICALCVSS 10.0EG 10.02026-02-11
A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie valu…
- CVE-2025-63414CRITICALCVSS 10.0EG 10.02025-12-16
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a maliciou…
- CVE-2025-58321CRITICALCVSS 10.0EG 10.02025-09-11
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
- CVE-2025-54261CRITICALCVSS 10.0EG 10.02025-09-09
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution by an attacker. The victim…
- CVE-2024-13984CRITICALCVSS 10.0EG 10.02025-08-27
QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rpts…
- CVE-2024-13981CRITICALCVSS 10.0EG 10.02025-08-27
LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint. This flaw affects the LiveBOS Server component …
- CVE-2023-7309CRITICALCVSS 10.0EG 10.02025-08-27
A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows…
- CVE-2025-9118CRITICALCVSS 10.0EG 10.02025-08-25
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
- CVE-2025-34040CRITICALCVSS 10.0EG 10.02025-06-24
An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers …
- CVE-2025-52562CRITICALCVSS 10.0EG 10.02025-06-23
Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a directory traversal vulnerability in the LocaleController component of Performave Convoy. An unauthenticated remote attacker …
- CVE-2025-26615CRITICALCVSS 10.0EG 10.02025-02-18
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to …
- CVE-2025-24786CRITICALCVSS 10.0EG 10.02025-02-06
WhoDB is an open source database management tool. While the application only displays Sqlite3 databases present in the directory `/db`, there is no path traversal prevention in place. This allows an unauthenticated attacker to open any Sql…
- CVE-2024-51549CRITICALCVSS 10.0EG 10.02024-12-05
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-43955CRITICALCVSS 10.0EG 10.02024-08-29
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themeum Droip allows File Manipulation.This issue affects Droip: from n/a through 1.1.1.
- CVE-2024-40629CRITICALCVSS 10.0EG 10.02024-07-18
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploi…
- CVE-2024-40628CRITICALCVSS 10.0EG 10.02024-07-18
JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints through a web browser. An attacker can exploi…
- CVE-2024-37902CRITICALCVSS 10.0EG 10.02024-06-17
DeepJavaLibrary(DJL) is an Engine-Agnostic Deep Learning Framework in Java. DJL versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files.…
- CVE-2024-2227CRITICALCVSS 10.0EG 10.02024-03-22
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained …
- CVE-2024-23652CRITICALCVSS 10.0EG 10.02024-01-31
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created f…
- CVE-2023-26045CRITICALCVSS 10.0EG 10.02023-07-24
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specia…
- CVE-2023-2825CRITICALCVSS 10.0EG 10.02023-05-26
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested…
- CVE-2022-1518CRITICALCVSS 10.0EG 10.02022-06-24
LRM contains a directory traversal vulnerability that can allow a malicious actor to upload outside the intended directory structure.
- CVE-2021-38454CRITICALCVSS 10.0EG 10.02021-10-12
A path traversal vulnerability in the Moxa MXview Network Management software Versions 3.x to 3.2.2 may allow an attacker to create or overwrite critical files used to execute code, such as programs or libraries.
- CVE-2020-29495CRITICALCVSS 10.0EG 10.02021-01-14
DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS …
- CVE-2019-18253CRITICALCVSS 10.0EG 10.02019-11-27
An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.
- CVE-2017-12815CRITICALCVSS 10.0EG 10.02018-03-26
Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a path traversal vulnerability. The archive can be downloaded from a given Bomgar Remote Support Portal deployment at htt…
- CVE-2026-70200CRITICALCVSS 9.8EG 10.02026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →