CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,476 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 106 of 190
- CVE-2023-23838MEDIUMCVSS 6.5EG 6.52023-04-25
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
- CVE-2023-23842HIGHCVSS 7.2EG 7.22023-07-26
The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.
- CVE-2023-23872MEDIUMCVSS 4.9EG 4.92024-05-17
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in German Mesky GMAce allows Path Traversal.This issue affects GMAce: from n/a through 1.5.2.
- CVE-2023-23888HIGHCVSS 7.6EG 7.62024-05-17
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rank Math Rank Math SEO allows Path Traversal.This issue affects Rank Math SEO: from n/a through 1.0.107.2.
- CVE-2023-23907HIGHCVSS 7.5EG 7.52023-07-06
A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerabil…
- CVE-2023-23946MEDIUMCVSS 6.2EG 6.22023-02-14
Git, a revision control system, is vulnerable to path traversal prior to versions 2.39.2, 2.38.4, 2.37.6, 2.36.5, 2.35.7, 2.34.7, 2.33.7, 2.32.6, 2.31.7, and 2.30.8. By feeding a crafted input to `git apply`, a path outside the working tre…
- CVE-2023-24057HIGHCVSS 8.1EG 8.12023-01-26
HL7 (Health Level 7) FHIR Core Libraries before 5.6.92 allow attackers to extract files into arbitrary directories via directory traversal from a crafted ZIP or TGZ archive (for a prepackaged terminology cache, NPM package, or comparison a…
- CVE-2023-24188CRITICALCVSS 9.1EG 9.12023-02-13
ureport v2.2.9 was discovered to contain a directory traversal vulnerability via the deletion function which allows for arbitrary files to be deleted.
- CVE-2023-24256HIGHCVSS 7.8EG 7.82023-07-06
An issue in the com.nextev.datastatistic component of NIO EC6 Aspen before v3.3.0 allows attackers to escalate privileges via path traversal.
- CVE-2023-2435HIGHCVSS 7.2EG 7.22023-05-31
The Blog-in-Blog plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.0 via a shortcode attribute. This allows editor-level, and above, attackers to include and execute arbitrary files on the ser…
- CVE-2023-24379MEDIUMCVSS 6.8EG 6.82024-05-17
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Web-Settler Landing Page Builder – Free Landing Page Templates allows Path Traversal.This issue affects Landing Page Builder – Free Landing…
- CVE-2023-24416MEDIUMCVSS 6.8EG 6.82024-02-23
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Arne Franken All In One Favicon.This issue affects All In One Favicon: from n/a through 4.7.
- CVE-2023-24449MEDIUMCVSS 4.3EG 4.32023-01-26
Jenkins PWauth Security Realm Plugin 0.4 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file pat…
- CVE-2023-24455MEDIUMCVSS 4.3EG 4.32023-01-26
Jenkins visualexpert Plugin 1.3 and earlier does not restrict the names of files in methods implementing form validation, allowing attackers with Item/Configure permission to check for the existence of an attacker-specified file path on th…
- CVE-2023-24592HIGHCVSS 7.3EG 7.32023-11-14
Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-24689MEDIUMCVSS 4.3EG 4.32023-02-09
An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx
- CVE-2023-24698HIGHCVSS 7.5EG 7.52023-08-08
Insufficient parameter validation in the Foswiki::Sandbox component of Foswiki v2.1.7 and below allows attackers to perform a directory traversal via supplying a crafted web request.
- CVE-2023-24804MEDIUMCVSS 5.0EG 5.02023-02-13
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Prior to version 3.0, the app has an incomplete fix for a path traversal issue and is vulnerable to two bypass methods. The bypasses may lead to i…
- CVE-2023-24815MEDIUMCVSS 4.8EG 4.82023-02-09
Vert.x-Web is a set of building blocks for building web applications in the java programming language. When running vertx web applications that serve files using `StaticHandler` on Windows Operating Systems and Windows File Systems, if the…
- CVE-2023-24836HIGHCVSS 8.8EG 8.82023-04-27
SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can exploit this vulnerability to upload and execute scripts onto arbitrary directories to per…
- CVE-2023-24960HIGHCVSS 7.5EG 7.52023-02-17
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.…
- CVE-2023-25050HIGHCVSS 7.1EG 7.12024-05-17
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vova Anokhin Shortcodes Ultimate allows Absolute Path Traversal.This issue affects Shortcodes Ultimate: from n/a through 5.12.6.
- CVE-2023-25186MEDIUMCVSS 5.1EG 5.12023-06-16
An issue was discovered on NOKIA Airscale ASIKA Single RAN devices before 21B. If/when CSP (as a BTS administrator) removes security hardenings from a Nokia Single RAN BTS baseband unit, a directory path traversal in the Nokia BTS baseband…
- CVE-2023-25265HIGHCVSS 7.5EG 7.52023-02-28
Docmosis Tornado <= 2.9.4 is vulnerable to Directory Traversal leading to the disclosure of arbitrary content on the file system.
- CVE-2023-25289HIGHCVSS 7.5EG 7.52023-05-04
Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.65792 in embedded web server, allows attacker to gain sensitive information via a crafted GET request.
- CVE-2023-25303HIGHCVSS 7.1EG 7.12023-04-04
ATLauncher <= 3.4.26.0 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory.
- CVE-2023-25304HIGHCVSS 7.8EG 7.82023-03-06
An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file.
- CVE-2023-25305HIGHCVSS 7.1EG 7.12023-04-04
PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory.
- CVE-2023-25306HIGHCVSS 7.5EG 7.52023-06-26
MultiMC Launcher <= 0.6.16 is vulnerable to Directory Traversal.
- CVE-2023-25307HIGHCVSS 7.8EG 7.82023-06-26
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
- CVE-2023-25341MEDIUMCVSS 6.5EG 6.52024-03-28
A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.
- CVE-2023-25345HIGHCVSS 7.5EG 7.52023-03-15
Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
- CVE-2023-25508MEDIUMCVSS 6.7EG 6.72023-04-22
NVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and download arbitrary files under certain circumstances, which may lead to denial of service, escalati…
- CVE-2023-25579MEDIUMCVSS 6.0EG 6.02023-02-22
Nextcloud server is a self hosted home cloud product. In affected versions the `OC\Files\Node\Folder::getFullPath()` function was validating and normalizing the string in the wrong order. The function is used in the `newFile()` and `newFol…
- CVE-2023-25606MEDIUMCVSS 6.5EG 6.52023-07-11
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions may allow a remo…
- CVE-2023-25652HIGHCVSS 7.5EG 8.12023-04-25
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to `git apply --reject`, a path outside the working tree can…
- CVE-2023-25688MEDIUMCVSS 4.3EG 5.32023-03-22
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to…
- CVE-2023-25689MEDIUMCVSS 2.7EG 5.32023-03-21
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1 , and 4.1.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) …
- CVE-2023-25750MEDIUMCVSS 4.3EG 4.32023-06-02
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.
- CVE-2023-25802HIGHCVSS 7.5EG 7.52023-03-13
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.6.0 don't correctly neutralize `dir/../filename` sequences, such as `/etc/nginx/../passwd`, allowing an actor to gain information…
- CVE-2023-25803HIGHCVSS 7.5EG 7.52023-03-13
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a directory traversal vulnerability that allows the inclusion of server-side files. This issue is fixed in version 6.3.5…
- CVE-2023-25804HIGHCVSS 7.5EG 7.52023-03-15
Roxy-WI is a Web interface for managing Haproxy, Nginx, Apache, and Keepalived servers. Versions prior to 6.3.5.0 have a limited path traversal vulnerability. An SSH key can be saved into an unintended location, for example the `/tmp` fold…
- CVE-2023-25814HIGHCVSS 7.1EG 7.12023-03-09
metersphere is an open source continuous testing platform. In versions prior to 2.7.1 a user who has permission to create a resource file through UI operations is able to append a path to their submission query which will be read by the sy…
- CVE-2023-25815LOWCVSS 3.3EG 3.32023-04-25
In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-p…
- CVE-2023-25914CRITICALCVSS 8.8EG 9.92023-08-21
Due to improper restriction, authenticated attackers could retrieve and read system files of the underlying server through the XML interface. The information that can be read can lead to a full system compromise.
- CVE-2023-26045CRITICALCVSS 10.0EG 10.02023-07-24
NodeBB is Node.js based forum software. Starting in version 2.5.0 and prior to version 2.8.7, due to the use of the object destructuring assignment syntax in the user export code path, combined with a path traversal vulnerability, a specia…
- CVE-2023-26101HIGHCVSS 7.5EG 7.52023-04-21
In Progress Flowmon Packet Investigator before 12.1.0, a Flowmon user with access to Flowmon Packet Investigator could leverage a path-traversal vulnerability to retrieve files on the Flowmon appliance's local filesystem.
- CVE-2023-26111HIGHCVSS 7.5EG 7.52023-03-06
All versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
- CVE-2023-26126HIGHCVSS 7.5EG 7.52023-05-10
All versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested via the requestFile function.
- CVE-2023-26152HIGHCVSS 7.5EG 7.52023-10-03
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →