CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,430 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 39 of 189
- CVE-2016-10184HIGHCVSS 7.5EG 7.52017-01-30
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.
- CVE-2016-10330HIGHCVSS 7.1EG 7.12017-05-12
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
- CVE-2016-10331HIGHCVSS 7.5EG 7.52017-05-12
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
- CVE-2016-10367HIGHCVSS 7.5EG 7.52017-05-03
In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch), an unauthenticated Directory Traversal vulnerability can be exploited by issuing a speciall…
- CVE-2016-10400HIGHCVSS 7.5EG 7.52017-07-22
Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arbitrary file by visiting get_course_icon.php?id= after the traversal attack.
- CVE-2016-10528MEDIUMCVSS 4.9EG 4.92018-05-31
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it speci…
- CVE-2016-10538LOWCVSS 3.5EG 3.52018-05-31
The package `node-cli` before 1.0.0 insecurely uses the lock_file and log_file. Both of these are temporary, but it allows the starting user to overwrite any file they have access to.
- CVE-2016-10561MEDIUMCVSS 5.3EG 5.32018-05-31
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.
- CVE-2016-10726HIGHCVSS 7.5EG 7.52018-07-10
The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Refere…
- CVE-2016-10733CRITICALCVSS 9.8EG 9.82018-10-29
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
- CVE-2016-10751HIGHCVSS 7.2EG 7.22019-05-24
osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote PHP code execution because an administrator can upload an image that contains PHP code in the EXIF data via index.php?pa…
- CVE-2016-10759CRITICALCVSS 9.8EG 9.82019-05-24
The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileManager/Classes/ExtendedFileManager.php because ExtendedFileManager can be used to rename the .htaccess file that blocks …
- CVE-2016-10828HIGHCVSS 8.8EG 8.82019-08-01
cPanel before 55.9999.141 allows arbitrary code execution because of an unsafe @INC path (SEC-97).
- CVE-2016-10924HIGHCVSS 7.5EG 7.52019-08-22
The ebook-download plugin before 1.2 for WordPress has directory traversal.
- CVE-2016-10965HIGHCVSS 7.5EG 7.52019-09-16
The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
- CVE-2016-10966HIGHCVSS 7.5EG 7.52019-09-16
The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
- CVE-2016-10977MEDIUMCVSS 6.5EG 6.52019-09-17
The nelio-ab-testing plugin before 4.5.0 for WordPress has filename=..%2f directory traversal.
- CVE-2016-1145HIGHCVSS 7.5EG 7.52016-01-30
Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors.
- CVE-2016-1191MEDIUMCVSS 5.3EG 5.32016-06-19
Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.
- CVE-2016-1192MEDIUMCVSS 4.3EG 4.32016-06-19
Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.
- CVE-2016-1212LOWCVSS 2.7EG 2.72016-06-05
Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.
- CVE-2016-1223MEDIUMCVSS 5.3EG 5.32016-06-19
Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.
- CVE-2016-1231MEDIUMCVSS 5.9EG 5.92016-01-12
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
- CVE-2016-1429HIGHCVSS 7.5EG 7.52016-08-08
Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023.
- CVE-2016-1434MEDIUMCVSS 6.5EG 6.52016-06-23
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.
- CVE-2016-15017CRITICALCVSS 5.5EG 9.82023-01-10
A vulnerability has been found in fabarea media_upload on TYPO3 and classified as critical. This vulnerability affects the function getUploadedFileList of the file Classes/Service/UploadFileService.php. The manipulation leads to pathname t…
- CVE-2016-15019HIGHCVSS 4.3EG 7.52023-01-15
A vulnerability was found in tombh jekbox. It has been rated as problematic. This issue affects some unknown processing of the file lib/server.rb. The manipulation leads to exposure of information through directory listing. The attack may …
- CVE-2016-15023MEDIUMCVSS 3.5EG 5.32023-01-31
A vulnerability, which was classified as problematic, was found in SiteFusion Application Server up to 6.6.6. This affects an unknown part of the file getextension.php of the component Extension Handler. The manipulation leads to path trav…
- CVE-2016-15038MEDIUMCVSS 6.5EG 6.52024-04-01
A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to l…
- CVE-2016-15055HIGHCVSS 8.7EG 8.72025-11-12
JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory traversal vulnerability in the checkcgi endpoint that accepts a user-controlled file parameter. An unauthenticated remote…
- CVE-2016-1525HIGHCVSS 8.6EG 8.92016-02-13
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.
- CVE-2016-1593HIGHCVSS 7.2EG 8.32016-04-22
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a mult…
- CVE-2016-1605MEDIUMCVSS 6.5EG 6.52016-08-01
Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.
- CVE-2016-1610HIGHCVSS 7.5EG 7.52016-08-01
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a …
- CVE-2016-1671HIGHCVSS 8.1EG 8.12016-05-14
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.
- CVE-2016-20023MEDIUMCVSS 5.0EG 5.02025-12-05
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
- CVE-2016-20040HIGHCVSS 8.4EG 8.42026-03-28
TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu com…
- CVE-2016-20041HIGHCVSS 8.4EG 8.42026-03-28
Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload c…
- CVE-2016-20048HIGHCVSS 8.4EG 8.42026-03-28
iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized value to the -k/--key parameter. Attackers can craft a malicious argument containing a NOP sl…
- CVE-2016-20076HIGHCVSS 7.5EG 7.52026-06-15
WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating the delete_backup_file and download_backup_file parameters in tool…
- CVE-2016-20081HIGHCVSS 7.5EG 7.52026-06-15
WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-downlo…
- CVE-2016-2087HIGHCVSS 7.4EG 7.42017-01-18
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.
- CVE-2016-2097MEDIUMCVSS 5.3EG 5.32016-04-07
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a …
- CVE-2016-2205MEDIUMCVSS 5.7EG 5.72016-07-12
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x b…
- CVE-2016-2289HIGHCVSS 7.5EG 7.52016-04-01
Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently discover password hashes, via unspecified vectors.
- CVE-2016-2389HIGHCVSS 7.5EG 7.82016-02-16
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path …
- CVE-2016-2872MEDIUMCVSS 5.3EG 5.32016-07-02
Directory traversal vulnerability in IBM Security QRadar SIEM 7.2.x before 7.2.7 and QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to read arbitrary files via a crafted URL.
- CVE-2016-2933MEDIUMCVSS 6.8EG 6.82016-11-30
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request.
- CVE-2016-3151HIGHCVSS 7.5EG 7.52017-01-12
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows…
- CVE-2016-3972LOWCVSS 2.7EG 2.72016-04-18
Directory traversal vulnerability in the dotTailLogServlet in dotCMS before 3.5.1 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the fileName parameter.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →