CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,469 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 98 of 190
- CVE-2022-33995HIGHCVSS 7.5EG 7.52022-06-21
A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an arbitrary location.
- CVE-2022-34002MEDIUMCVSS 6.5EG 6.52022-09-16
The ‘document’ parameter of PDS Vista 7’s /application/documents/display.aspx page is vulnerable to a Local File Inclusion vulnerability which allows an low-privileged authenticated attacker to leak the configuration files and source…
- CVE-2022-34026HIGHCVSS 7.5EG 7.52022-09-22
ICEcoder v8.1 allows attackers to execute a directory traversal.
- CVE-2022-34126HIGHCVSS 7.5EG 7.52023-04-16
The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.
- CVE-2022-34127HIGHCVSS 7.5EG 7.52023-04-16
The Managentities plugin before 4.0.2 for GLPI allows reading local files via directory traversal in the inc/cri.class.php file parameter.
- CVE-2022-34177HIGHCVSS 7.5EG 7.52022-06-23
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a r…
- CVE-2022-34179HIGHCVSS 7.5EG 7.52022-06-23
Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to choose a different SVG image style without restricting possible values, resulting in a relative path traversal vulnerabili…
- CVE-2022-34254HIGHCVSS 8.8EG 8.82022-08-16
Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could be abused by an attac…
- CVE-2022-34271HIGHCVSS 8.8EG 8.82022-12-14
A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0.
- CVE-2022-34365MEDIUMCVSS 6.5EG 6.52022-08-10
WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web …
- CVE-2022-34373HIGHCVSS 7.3EG 7.82022-08-31
Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary …
- CVE-2022-34375HIGHCVSS 8.8EG 8.82022-08-30
Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path…
- CVE-2022-34378MEDIUMCVSS 5.5EG 5.52022-09-02
Dell PowerScale OneFS, versions 9.0.0 up to and including 9.1.0.20, 9.2.1.13, 9.3.0.6, and 9.4.0.3, contain a relative path traversal vulnerability. A low privileged local attacker could potentially exploit this vulnerability, leading to d…
- CVE-2022-34426HIGHCVSS 8.8EG 8.82022-10-11
Dell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries which could lead to OS command injection. A remote unauthenticated attacker could exploit this vuln…
- CVE-2022-34429HIGHCVSS 6.5EG 7.12022-09-30
Dell Hybrid Client below 1.8 version contains a Zip Slip Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.
- CVE-2022-34430HIGHCVSS 7.1EG 7.52022-10-11
Dell Hybrid Client below 1.8 version contains a Zip Bomb Vulnerability in UI. A guest privilege attacker could potentially exploit this vulnerability, leading to system files modification.
- CVE-2022-34486HIGHCVSS 7.2EG 7.22022-08-23
Path traversal vulnerability in PukiWiki versions 1.4.5 to 1.5.3 allows a remote authenticated attacker with an administrative privilege to execute a malicious script via unspecified vectors.
- CVE-2022-34551MEDIUMCVSS 6.5EG 6.52022-07-27
Sims v1.0 was discovered to allow path traversal when downloading attachments.
- CVE-2022-34662MEDIUMCVSS 6.5EG 6.52022-11-01
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
- CVE-2022-34762HIGHCVSS 5.9EG 7.52022-07-13
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products…
- CVE-2022-34822CRITICALCVSS 9.8EG 9.82022-11-08
Path traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 5.0 SingleServerSafe for Windows and earlie…
- CVE-2022-34836HIGHCVSS 5.9EG 8.22022-08-24
Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability coul…
- CVE-2022-34855MEDIUMCVSS 6.7EG 6.72023-05-10
Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-35204MEDIUMCVSS 4.3EG 4.32022-08-18
Vitejs Vite before v2.9.13 was discovered to allow attackers to perform a directory traversal via a crafted URL to the victim's service.
- CVE-2022-35216HIGHCVSS 7.5EG 7.52022-08-04
OMICARD EDM’s mail image relay function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to by-pass authentication and access arbitrary system files.
- CVE-2022-35235MEDIUMCVSS 4.9EG 4.92022-08-23
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
- CVE-2022-35410HIGHCVSS 7.5EG 7.52022-07-08
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted ar…
- CVE-2022-3560MEDIUMCVSS 5.5EG 5.52023-02-02
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in t…
- CVE-2022-35650HIGHCVSS 7.5EG 8.02022-07-25
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform director…
- CVE-2022-35861HIGHCVSS 7.8EG 7.82022-07-17
pyenv 1.2.24 through 2.3.2 allows local users to gain privileges via a .python-version file in the current working directory. An attacker can craft a Python version string in .python-version to execute shims under their control. (Shims are…
- CVE-2022-35908CRITICALCVSS 8.8EG 9.82023-09-29
Cambium Enterprise Wi-Fi System Software before 6.4.2 does not sanitize the ping host argument in device-agent.
- CVE-2022-35918MEDIUMCVSS 6.5EG 6.52022-08-01
Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such…
- CVE-2022-35919HIGHCVSS 7.4EG 8.02022-08-01
MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. In affected versions all 'admin' users authorized for `admin:ServerUpdate` can selectively trigger an error that in response, returns the con…
- CVE-2022-35920HIGHCVSS 8.3EG 8.32022-08-01
Sanic is an opensource python web server/framework. Affected versions of sanic allow access to lateral directories when using `app.static` if using encoded `%2F` URLs. Parent directory traversal is not impacted. Users are advised to upgrad…
- CVE-2022-36007MEDIUMCVSS 6.1EG 6.12022-08-15
Venice is a Clojure inspired sandboxed Lisp dialect with excellent Java interoperability. A partial path traversal issue exists within the functions `load-file` and `load-resource`. These functions can be limited to load files from a list …
- CVE-2022-36035HIGHCVSS 7.7EG 7.72022-08-31
Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to deploy. Flux CLI allows users to deploy Flux components into a …
- CVE-2022-36065HIGHCVSS 7.5EG 7.52022-09-06
GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new accounts and upload files to arbitrary directories within the cont…
- CVE-2022-36081HIGHCVSS 7.5EG 7.52022-09-07
Wikmd is a file based wiki that uses markdown. Prior to version 1.7.1, Wikmd is vulnerable to path traversal when accessing `/list/<path:folderpath>` and discloses lists of files located on the server including sensitive data. Version 1.7.…
- CVE-2022-36113MEDIUMCVSS 4.6EG 4.62022-09-14
Cargo is a package manager for the rust programming language. After a package is downloaded, Cargo extracts its source code in the ~/.cargo folder on disk, making it available to the Rust projects it builds. To record when an extraction is…
- CVE-2022-36168LOWCVSS 2.7EG 2.72022-08-26
A directory traversal vulnerability was discovered in Wuzhicms 4.1.0. via /coreframe/app/attachment/admin/index.php:
- CVE-2022-36221MEDIUMCVSS 6.5EG 6.52022-12-21
Nokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe file on the system.
- CVE-2022-36243MEDIUMCVSS 5.3EG 5.32023-05-30
Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This i…
- CVE-2022-36261CRITICALCVSS 9.1EG 9.12022-08-23
An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt
- CVE-2022-36327MEDIUMCVSS 5.8EG 5.82023-05-18
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in…
- CVE-2022-36328MEDIUMCVSS 5.8EG 5.82023-05-18
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device confi…
- CVE-2022-36400HIGHCVSS 6.7EG 7.82022-11-11
Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36593MEDIUMCVSS 6.5EG 6.52022-09-02
kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.
- CVE-2022-36687MEDIUMCVSS 6.5EG 6.52022-08-29
Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.
- CVE-2022-36831MEDIUMCVSS 6.2EG 6.22022-08-05
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
- CVE-2022-36850MEDIUMCVSS 4.0EG 4.72022-09-09
Path traversal vulnerability in CallBGProvider prior to SMR Sep-2022 Release 1 allows attacker to overwrite arbitrary file with phone uid.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →