CWE-22 · 9,994 records
Path traversal
Why does it happen?
A user-supplied file name is joined with the allowed directory, but the result is never checked to confirm it is still inside that directory.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
const file = path.join(ROOT, req.query.name);res.sendFile(file);Fixed
const file = path.resolve(ROOT, req.query.name);if (!file.startsWith(ROOT + path.sep)) { return res.sendStatus(400);}res.sendFile(file);How to prevent it
- 01After resolving the path, verify it stays within the root directory.
- 02Serve files by database ID rather than by name.
- 03Run the server process with read access only to the directories it needs.
CVEs in this class
10,000 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2019-11510Weaponized | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Critical10.0 | KEV | 100.0% | May 8, 2019 |
99Now | CVE-2022-29464Weaponized | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Critical9.8 | KEV | 100.0% | Apr 18, 2022 |
99Now | CVE-2021-22005Weaponized | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 100.0% | Sep 23, 2021 |
99Now | CVE-2020-5902Weaponized | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Intef5 · big-ip access policy manager · CWE-22 | Critical9.8 | KEV | 100.0% | Jul 1, 2020 |
99Now | CVE-2024-23897Weaponized | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character follojenkins · jenkins · CWE-22 | Critical9.8 | KEV | 100.0% | Jan 24, 2024 |
99Now | CVE-2019-19781Weaponized | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.citrix · application delivery controller firmware · CWE-22 | Critical9.8 | KEV | 100.0% | Dec 27, 2019 |
99Now | CVE-2018-13379Weaponized | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4fortinet · fortiproxy · CWE-22 | Critical9.8 | KEV | 100.0% | Jun 4, 2019 |
99Now | CVE-2021-41773Weaponized | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 5, 2021 |
99Now | CVE-2021-20090Weaponized | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= buffalo · wsr-2533dhpl2-bk firmware · CWE-22 | Critical9.8 | KEV | 100.0% | Apr 29, 2021 |
99Now | CVE-2021-42013Weaponized | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Critical9.8 | KEV | 100.0% | Oct 7, 2021 |
99Now | CVE-2024-32113Weaponized | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Critical9.8 | KEV | 99.9% | May 8, 2024 |
99Now | CVE-2019-3396Weaponized | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1atlassian · confluence server · CWE-22 | Critical9.8 | KEV | 99.9% | Mar 25, 2019 |
99Now | CVE-2021-21972Weaponized | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.vmware · cloud foundation · CWE-22 | Critical9.8 | KEV | 99.9% | Feb 24, 2021 |
99Now | CVE-2010-2861Weaponized | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to readobe · coldfusion · CWE-22 | Critical9.8 | KEV | 99.7% | Aug 11, 2010 |
99Now | CVE-2024-4885Weaponized | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-22 | Critical9.8 | KEV | 99.3% | Jun 25, 2024 |
99Now | CVE-2019-16278Weaponized | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a cnazgul · nostromo nhttpd · CWE-22 | Critical9.8 | KEV | 99.0% | Oct 14, 2019 |
99Now | CVE-2023-47246Weaponized | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat wesysaid · sysaid · CWE-22 | Critical9.8 | KEV | 98.9% | Nov 10, 2023 |
98Now | CVE-2022-41352Weaponized | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.synacor · zimbra collaboration suite · CWE-22 | Critical9.8 | KEV | 95.5% | Sep 25, 2022 |
97Now | CVE-2024-7399Weaponized | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attacksamsung · magicinfo 9 server · CWE-22 | Critical9.8 | KEV | 91.9% | Aug 12, 2024 |
97Now | CVE-2022-37042Weaponized | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.synacor · zimbra collaboration suite · CWE-22 | Critical9.8 | KEV | 91.9% | Aug 12, 2022 |
97Now | CVE-2026-85706Weaponized | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab · gitlab · CWE-22 | Critical10.0 | KEV | 91.4% | Sep 11, 2026 |
96Now | CVE-2024-8963Weaponized | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.ivanti · endpoint manager cloud services appliance · CWE-22 | Critical9.1 | KEV | 98.6% | Sep 19, 2024 |
96Now | CVE-2025-34028Weaponized | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversalcommvault · commvault · CWE-22 | Critical9.3 | KEV | 97.6% | Apr 22, 2025 |
96Now | CVE-2019-7195Weaponized | This external control of file name or path vulnerability allows remote attackers to access or modify system files.qnap · photo station · CWE-22 | Critical9.8 | KEV | 89.7% | Dec 5, 2019 |
95Now | CVE-2024-41713Weaponized | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthentimitel · micollab · CWE-22 | Critical9.1 | KEV | 98.1% | Oct 21, 2024 |
- CVE-2019-11510100Now
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · connect secureMay 8, 2019
- CVE-2022-2946499Now
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%wso2 · api managerApr 18, 2022
- CVE-2021-2200599Now
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationSep 23, 2021
- CVE-2020-590299Now
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte
CriticalCVSS 9.8KEVWeaponizedEPSS 100%f5 · big-ip access policy managerJul 1, 2020
- CVE-2024-2389799Now
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character follo
CriticalCVSS 9.8KEVWeaponizedEPSS 100%jenkins · jenkinsJan 24, 2024
- CVE-2019-1978199Now
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%citrix · application delivery controller firmwareDec 27, 2019
- CVE-2018-1337999Now
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4
CriticalCVSS 9.8KEVWeaponizedEPSS 100%fortinet · fortiproxyJun 4, 2019
- CVE-2021-4177399Now
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 5, 2021
- CVE-2021-2009099Now
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=
CriticalCVSS 9.8KEVWeaponizedEPSS 100%buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021
- CVE-2021-4201399Now
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · http serverOct 7, 2021
- CVE-2024-3211399Now
Apache OFBiz: Path traversal leading to RCE
CriticalCVSS 9.8KEVWeaponizedEPSS 100%apache · ofbizMay 8, 2024
- CVE-2019-339699Now
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1
CriticalCVSS 9.8KEVWeaponizedEPSS 100%atlassian · confluence serverMar 25, 2019
- CVE-2021-2197299Now
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · cloud foundationFeb 24, 2021
- CVE-2010-286199Now
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re
CriticalCVSS 9.8KEVWeaponizedEPSS 100%adobe · coldfusionAug 11, 2010
- CVE-2024-488599Now
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 99%progress · whatsup goldJun 25, 2024
- CVE-2019-1627899Now
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c
CriticalCVSS 9.8KEVWeaponizedEPSS 99%nazgul · nostromo nhttpdOct 14, 2019
- CVE-2023-4724699Now
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sysaid · sysaidNov 10, 2023
- CVE-2022-4135298Now
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.
CriticalCVSS 9.8KEVWeaponizedEPSS 95%synacor · zimbra collaboration suiteSep 25, 2022
- CVE-2024-739997Now
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attack
CriticalCVSS 9.8KEVWeaponizedEPSS 92%samsung · magicinfo 9 serverAug 12, 2024
- CVE-2022-3704297Now
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
CriticalCVSS 9.8KEVWeaponizedEPSS 92%synacor · zimbra collaboration suiteAug 12, 2022
- CVE-2026-8570697Now
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
CriticalCVSS 10.0KEVWeaponizedEPSS 91%gitlab · gitlabSep 11, 2026
- CVE-2024-896396Now
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
CriticalCVSS 9.1KEVWeaponizedEPSS 99%ivanti · endpoint manager cloud services applianceSep 19, 2024
- CVE-2025-3402896Now
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
CriticalCVSS 9.3KEVWeaponizedEPSS 98%commvault · commvaultApr 22, 2025
- CVE-2019-719596Now
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
CriticalCVSS 9.8KEVWeaponizedEPSS 90%qnap · photo stationDec 5, 2019
- CVE-2024-4171395Now
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti
CriticalCVSS 9.1KEVWeaponizedEPSS 98%mitel · micollabOct 21, 2024