CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
10,495 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 6 of 210
- CVE-2023-38702CRITICALCVSS 9.9EG 9.92023-08-04
Knowage is an open source analytics and business intelligence suite. Starting in the 6.x.x branch and prior to version 8.1.8, the endpoint `/knowage/restful-services/dossier/importTemplateFile` allows authenticated users to upload `templat…
- CVE-2023-36460CRITICALCVSS 9.9EG 9.92023-07-06
Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code t…
- CVE-2022-45092CRITICALCVSS 9.9EG 9.92023-01-10
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary fil…
- CVE-2022-32573CRITICALCVSS 9.9EG 9.92022-12-15
A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger…
- CVE-2022-29517CRITICALCVSS 9.9EG 9.92022-12-15
A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request t…
- CVE-2022-30547CRITICALCVSS 9.9EG 9.92022-08-22
A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP reque…
- CVE-2022-24877CRITICALCVSS 9.9EG 9.92022-05-06
Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to expose sensitive data from the controller’s pod filesystem …
- CVE-2022-24900CRITICALCVSS 9.9EG 9.92022-04-29
Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untruste…
- CVE-2021-32008CRITICALCVSS 9.9EG 9.92022-03-04
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories.
- CVE-2022-21675CRITICALCVSS 9.9EG 9.92022-01-12
Bytecode Viewer (BCV) is a Java/Android reverse engineering suite. Versions of the package prior to 2.11.0 are vulnerable to Arbitrary File Write via Archive Extraction (AKA "Zip Slip"). The vulnerability is exploited using a specially cra…
- CVE-2021-40358CRITICALCVSS 9.9EG 9.92021-11-09
A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC04), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP1), SIMATIC WinCC V15 and earlier (All versions < V15 SP1 Update 7), SIM…
- CVE-2021-32016CRITICALCVSS 9.9EG 9.92021-08-03
An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to a user-controlled location on the remote filesystem (with user-controlled content) via directory traversal, potentially…
- CVE-2021-25311CRITICALCVSS 9.9EG 9.92021-01-27
condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, as demonstrated by creating a file under /etc that will later be executed by root.
- CVE-2018-19586CRITICALCVSS 9.9EG 9.92019-04-09
Silverpeas 5.15 through 6.0.2 is affected by an authenticated Directory Traversal vulnerability that can be triggered during file uploads because core/webapi/upload/FileUploadData.java mishandles a StringUtil.java call. This vulnerability …
- CVE-2018-16367CRITICALCVSS 9.9EG 9.92018-09-02
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
- CVE-2017-14804CRITICALCVSS 9.9EG 9.92018-03-01
The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots.
- CVE-2024-33109CRITICALCVSS 9.8EG 9.92024-09-19
Directory Traversal in the web interface of the Tiptel IP 286 with firmware version 2.61.13.10 allows attackers to overwrite arbitrary files on the phone via the Ringtone upload function.
- CVE-2024-44761CRITICALCVSS 9.8EG 9.92024-08-28
An issue in EQ Enterprise Management System before v2.0.0 allows attackers to execute a directory traversal via crafted requests.
- CVE-2023-42657CRITICALCVSS 9.6EG 9.92023-09-27
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a directory traversal vulnerability was discovered. An attacker could leverage this vulnerability to perform file operations (delete, rename, rmdir, mkdir) on files and folders outsi…
- CVE-2026-2749CRITICALCVSS 8.8EG 9.92026-02-27
Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7.
- CVE-2026-0963CRITICALCVSS 8.8EG 9.92026-01-30
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
- CVE-2023-25914CRITICALCVSS 8.8EG 9.92023-08-21
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
- CVE-2026-32938CRITICALCVSS 6.5EG 9.92026-03-20
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, the /api/lute/html2BlockDOM on the desktop copies local files pointed to by file:// links in pasted HTML into the workspace assets directory without validating …
- CVE-2026-105892CRITICALCVSS 9.8EG 9.82026-10-10
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in rtCamp Inc. rtMedia for WordPress, BuddyPress and bbPress buddypress-media allows Path Traversal.This issue affects rtMedia for WordPress, Budd…
- CVE-2026-75875CRITICALCVSS 9.8EG 9.82026-10-08
IBM Guardium Data Protection 12.0, 12.1, and 12.2 could allow a remote attacker to execute arbitrary code due to path traversal.
- CVE-2026-79805CRITICALCVSS 9.8EG 9.82026-10-06
An authenticated path traversal vulnerability exists in ClearPass Policy Manager. Successful exploitation could allow an attacker to read and modify certain files on the underlying operating system.
- CVE-2025-41753CRITICALCVSS 9.8EG 9.82026-10-01
The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outs…
- CVE-2026-51880CRITICALCVSS 9.8EG 9.82026-10-01
deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outside the intended bot workspace.
- CVE-2026-51884CRITICALCVSS 9.8EG 9.82026-10-01
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassi…
- CVE-2026-103044CRITICALCVSS 9.8EG 9.82026-09-29
XML injection (aka blind XPath injection) vulnerability in The Wikimedia Foundation Mediawiki - EasyTimeline extension allows XML Injection. This issue affects Mediawiki - EasyTimeline extension: before 1.46.1, 1.45.5, 1.43.10.
- CVE-2026-91012CRITICALCVSS 9.8EG 9.82026-09-29
org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the config:* shell commands, derives the file it writes a configuration to from caller-supplied input without checking that …
- CVE-2026-93643CRITICALCVSS 9.8EG 9.82026-09-25
When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zim…
- CVE-2026-96276CRITICALCVSS 9.8EG 9.82026-09-23
If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working di…
- CVE-2026-70009CRITICALCVSS 9.8EG 9.82026-09-17
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-45140CRITICALCVSS 9.8EG 9.82026-09-17
Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, co…
- CVE-2026-61560CRITICALCVSS 9.8EG 9.82026-09-15
`@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the …
- CVE-2026-89040CRITICALCVSS 9.8EG 9.82026-09-15
Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code a…
- CVE-2026-80131CRITICALCVSS 9.8EG 9.82026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated att…
- CVE-2026-80129CRITICALCVSS 9.8EG 9.82026-09-07
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated att…
- CVE-2026-85661CRITICALCVSS 9.8EG 9.82026-09-04
excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any fi…
- CVE-2026-78657CRITICALCVSS 9.8EG 9.82026-09-02
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This mak…
- CVE-2026-82460CRITICALCVSS 9.8EG 9.82026-08-29
Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, …
- CVE-2026-54687CRITICALCVSS 9.8EG 9.82026-08-27
n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflo…
- CVE-2026-47884CRITICALCVSS 9.8EG 9.82026-08-27
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Sprin…
- CVE-2026-37007CRITICALCVSS 9.8EG 9.82026-08-27
A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via malicious path traversal sequences in the filename argument.
- CVE-2026-75337CRITICALCVSS 9.8EG 9.82026-08-27
The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The user-controlled path is concatenated to the preview root directory without any normalization, allowing anonymous attacker…
- CVE-2026-80104CRITICALCVSS 9.8EG 9.82026-08-25
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename a…
- CVE-2026-19912CRITICALCVSS 9.8EG 9.82026-08-25
The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by unsafe data deserialization and unsanitized filesystem path construction. mwEmbedLoader.php accepts a user‑controlled…
- CVE-2026-53451CRITICALCVSS 9.8EG 9.82026-08-19
Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snap…
- CVE-2026-47627CRITICALCVSS 9.8EG 9.82026-08-18
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →