CWE-22— Path Traversal
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.— MITRE CWE catalog
9,454 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-22page 38 of 190
- CVE-2015-5468HIGHCVSS 7.5EG 7.52017-05-23
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.
- CVE-2015-5469HIGHCVSS 7.5EG 7.52017-05-23
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
- CVE-2015-5471MEDIUMCVSS 5.3EG 5.52016-01-12
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter.
- CVE-2015-5473CRITICALCVSS 9.8EG 9.82017-06-01
Multiple directory traversal vulnerabilities in Samsung SyncThru 6 before 1.0 allow remote attackers to delete arbitrary files via unspecified parameters to (1) upload/updateDriver or (2) upload/addDriver or to execute arbitrary code with …
- CVE-2015-5609CRITICALCVSS 9.1EG 9.12017-05-23
Absolute path traversal vulnerability in the Image Export plugin 1.1 for WordPress allows remote attackers to read and delete arbitrary files via a full pathname in the file parameter to download.php.
- CVE-2015-5952CRITICALCVSS 9.8EG 9.82020-01-15
Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.
- CVE-2015-6589HIGHCVSS 8.8EG 8.82020-02-13
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before 8.0.0.23, 9.0.0.0 before 9.0.0.19, and 9.1.0.0 before 9.1.0.9 allows remote authenticated users to write to and execute…
- CVE-2015-6591MEDIUMCVSS 5.5EG 5.52020-01-15
Directory traversal vulnerability in application/templates/amelia/loadjs.php in Free Reprintables ArticleFR 3.0.7 and earlier allows local users to read arbitrary files via the s parameter.
- CVE-2015-6833HIGHCVSS 7.5EG 7.52016-01-19
Directory traversal vulnerability in the PharData class in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 allows remote attackers to write to arbitrary files via a .. (dot dot) in a ZIP archive entry that is mishandled dur…
- CVE-2015-7245HIGHCVSS 7.5EG 7.92017-04-24
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.
- CVE-2015-7270HIGHCVSS 7.8EG 7.82017-04-10
Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 and 7/8 before 2.21.21.21 allows directory traversal.
- CVE-2015-7669CRITICALCVSS 9.8EG 9.82017-12-27
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfil…
- CVE-2015-7780MEDIUMCVSS 6.5EG 6.52017-06-27
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.
- CVE-2015-7851MEDIUMCVSS 6.5EG 6.52020-01-28
Directory traversal vulnerability in the save_config function in ntpd in ntp_control.c in NTP before 4.2.8p4, when used on systems that do not use '\' or '/' characters for directory separation such as OpenVMS, allows remote authenticated …
- CVE-2015-7888HIGHCVSS 7.5EG 7.52017-06-07
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, c…
- CVE-2015-8235HIGHCVSS 7.5EG 7.52017-06-07
Directory traversal vulnerability in Spiffy before 5.4.
- CVE-2015-8283MEDIUMCVSS 6.5EG 6.52017-04-13
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
- CVE-2015-8309MEDIUMCVSS 4.3EG 4.32017-03-27
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
- CVE-2015-8352CRITICALCVSS 9.8EG 9.82017-08-24
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.
- CVE-2015-8535HIGHCVSS 7.8EG 7.82020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 that cou…
- CVE-2015-8770HIGHCVSS 7.5EG 7.52016-01-29
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or pos…
- CVE-2015-8780MEDIUMCVSS 6.4EG 6.42017-04-13
Samsung wssyncmlnps before 2015-10-31 allows directory traversal in a Kies restore, aka ZipFury.
- CVE-2015-8794MEDIUMCVSS 6.5EG 6.52016-01-29
Absolute path traversal vulnerability in program/steps/addressbook/photo.inc in Roundcube before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary files via a full pathname in the _alt parameter, related to c…
- CVE-2015-8798HIGHCVSS 8.0EG 8.02016-06-08
Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 …
- CVE-2015-8799HIGHCVSS 7.6EG 7.62016-06-08
Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 …
- CVE-2015-9250HIGHCVSS 7.5EG 7.52018-01-12
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.
- CVE-2015-9266CRITICALCVSS 9.8EG 9.82018-09-05
The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exp…
- CVE-2015-9275MEDIUMCVSS 5.3EG 5.32019-01-07
ARC 5.21q allows directory traversal via a full pathname in an archive file.
- CVE-2015-9277CRITICALCVSS 9.1EG 9.12019-01-16
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
- CVE-2015-9287CRITICALCVSS 9.8EG 9.82019-05-13
Directory Traversal was discovered in University of Cambridge mod_ucam_webauth before 2.0.2. The key identification field ("kid") of the IdP's HTTP response message ("WLS-Response") can be manipulated by an attacker. The "kid" field is not…
- CVE-2015-9406HIGHCVSS 7.5EG 8.22019-09-20
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
- CVE-2015-9463HIGHCVSS 7.5EG 7.52019-10-10
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
- CVE-2015-9464HIGHCVSS 7.5EG 7.52019-10-10
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
- CVE-2015-9470HIGHCVSS 7.5EG 7.52019-10-10
The history-collection plugin through 1.1.1 for WordPress has directory traversal via the download.php var parameter.
- CVE-2015-9473HIGHCVSS 7.5EG 7.52019-10-10
The estrutura-basica theme through 2015-09-13 for WordPress has directory traversal via the scripts/download.php arquivo parameter.
- CVE-2015-9480HIGHCVSS 7.5EG 7.52019-10-10
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
- CVE-2015-9538MEDIUMCVSS 6.5EG 6.52019-11-26
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
- CVE-2015-9546MEDIUMCVSS 4.8EG 4.82020-04-10
An issue was discovered on Samsung mobile devices with KK(4.4) and later software through 2015-06-16. In some cases, HTTP is used for an Inputmethod, rather than HTTPS. A man-in-the-middle attacker can modify the client-server data stream …
- CVE-2016-0709HIGHCVSS 7.2EG 8.82016-04-11
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via…
- CVE-2016-0752CRITICALCVSS 7.5EG 9.0⚠ KEV2016-02-16
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an applica…
- CVE-2016-0784HIGHCVSS 6.5EG 7.72016-04-11
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.
- CVE-2016-0855HIGHCVSS 7.5EG 7.52016-01-15
Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.
- CVE-2016-1000112CRITICALCVSS 9.1EG 9.12016-10-06
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
- CVE-2016-10037HIGHCVSS 7.3EG 7.32016-12-24
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.
- CVE-2016-10038HIGHCVSS 7.3EG 7.32016-12-24
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.
- CVE-2016-10039HIGHCVSS 7.3EG 7.32016-12-24
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.
- CVE-2016-10048HIGHCVSS 7.5EG 7.52017-03-23
Directory traversal vulnerability in magick/module.c in ImageMagick 6.9.4-7 allows remote attackers to load arbitrary modules via unspecified vectors.
- CVE-2016-10106MEDIUMCVSS 6.5EG 6.52017-01-03
Directory traversal vulnerability in scgi-bin/platform.cgi on NETGEAR FVS336Gv3, FVS318N, FVS318Gv2, and SRX5308 devices with firmware before 4.3.3-8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the thisp…
- CVE-2016-10173HIGHCVSS 7.5EG 7.52017-02-01
Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a TAR archive entry.
- CVE-2016-10183HIGHCVSS 7.5EG 7.52017-01-30
An issue was discovered on the D-Link DWR-932B router. qmiweb allows directory listing with ../ traversal.
Map vulnerabilities like CWE-22 to your infrastructure
EchelonGraph correlates every CVE — across CWE-22 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →