Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3324

3324 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-7036 Tenda i9 HTTP R7WebsSecurityHandlerfunction path traversal — i9 7.3 High2026-04-26
CVE-2026-7024 rawchen sims deleteFileServlet Endpoint DeleteFileServlet.java path traversal — sims 5.4 Medium2026-04-26
CVE-2026-7020 Ollama Tensor Model Transfer transfer.go digestToPath path traversal — Ollama 5.6 Medium2026-04-26
CVE-2026-6968 Multiple Path Traversal Variants in awslabs/tough — tough 5.9 Medium2026-04-24
CVE-2026-41433 OpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIR — opentelemetry-ebpf-instrumentation 8.4 High2026-04-24
CVE-2026-41894 SiYuan: Incomplete Fix Bypass for CVE-2026-30869: Path Traversal via Double URL Encoding in `/export/` Endpoint — siyuan 6.5AIMediumAI2026-04-24
CVE-2026-41419 4ga Boards: Import Path Traversal Leads to Arbitrary File Read — 4gaBoards 7.6 High2026-04-24
CVE-2026-41140 Poetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4 — poetry 9.1AICriticalAI2026-04-24
CVE-2026-33077 Roxy-WI has an arbitrary file read vulnerability — roxy-wi 7.5AIHighAI2026-04-24
CVE-2026-33076 Roxy-WI vulnerable to path traversal and arbitrary file writing — roxy-wi 9.8AICriticalAI2026-04-24
CVE-2026-29051 melange has Path Traversal via .PKGINFO in --persist-lint-results — melange 4.4 Medium2026-04-24
CVE-2026-29050 melange has Path Traversal When Resolving External Pipelines via Unvalidated pipeline[].uses — melange 6.1 Medium2026-04-23
CVE-2026-6940 radare2 < 6.1.4 Project Deletion Path Traversal Directory Deletion — radare2 7.1 High2026-04-23
CVE-2026-41205 Mako: Path traversal via double-slash URI prefix in TemplateLookup — mako 9.1AICriticalAI2026-04-23
CVE-2026-6903 Path Traversal Vulnerability in LabOne User Interface — LabOne 7.5 High2026-04-23
CVE-2026-41211 `vite-plus/binding` has path traversal `downloadPackageManager()` that leads to writes outside of `VP_HOME` — vite-plus 6.5AIMediumAI2026-04-23
CVE-2026-41180 PsiTransfer: Upload PATCH path traversal can create `config.<NODE_ENV>.js` and lead to code execution on restart — psitransfer 7.5 High2026-04-23
CVE-2026-40062 Ziosoft Ziostation 路径遍历漏洞 — Ziostation2 7.5AIHighAI2026-04-23
CVE-2026-4917 IBM Guardium Data Protection is affected by multiple vulnerabilities — Guardium Data Protection 4.9 Medium2026-04-22
CVE-2026-33656 EspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin user — espocrm 9.1 Critical2026-04-22
CVE-2026-34414 Xerte Online Toolkits Path Traversal via connector.php — xerteonlinetoolkits 7.1 High2026-04-22
CVE-2026-32885 DDEV has ZipSlip path traversal in tar and zip archive extraction — ddev 6.5 Medium2026-04-22
CVE-2026-35363 uutils coreutils rm Safeguard Bypass via Improper Path Normalization — coreutils 5.6 Medium2026-04-22
CVE-2026-35338 uutils coreutils chmod Path Traversal Bypass of --preserve-root — coreutils 7.3 High2026-04-22
CVE-2026-6855 Instructlab: instructlab: path traversal allows arbitrary directory creation and file write — Red Hat Enterprise Linux AI (RHEL AI) 3 7.1 High2026-04-22
CVE-2026-4280 Breaking News WP <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Local File Inclusion/Read — Breaking News WP 6.5 Medium2026-04-22
CVE-2026-41062 WWBN/AVideo has an incomplete fix for a directory traversal bypass via query string in ReceiveImage downloadURL parameters — AVideo 6.5 Medium2026-04-21
CVE-2026-41058 AVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideo — AVideo 8.1 High2026-04-21
CVE-2026-6832 Nesquena Hermes WebUI Arbitrary File Deletion via Unvalidated session_id — hermes-webui 8.1 High2026-04-21
CVE-2026-6829 nesquena hermes-webui Arbitrary Workspace Directory Access — hermes-webui 6.3 Medium2026-04-21

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3324 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.