Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3327

3327 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2251 Path Traversal leading to Remote Code Execution (RCE) — FreeFlow Core 9.8 Critical2026-02-27
CVE-2026-3289 Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversal — PublicCMS 6.3 Medium2026-02-27
CVE-2026-22877 Copeland XWEB and XWEB Pro Path Traversal — Copeland XWEB 300D PRO 3.7 Low2026-02-27
CVE-2026-28208 Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on Linux/Unix — junrar 5.9 Medium2026-02-26
CVE-2026-23939 Path Traversal in Local File Store Backend — hexpm 9.1AICriticalAI2026-02-26
CVE-2026-26228 VLC for Android < 3.7.0 Remote Access Path Traversal — VLC for Android 4.9 Medium2026-02-26
CVE-2026-1311 Worry Proof Backup <= 0.2.4 - Authenticated (Subscriber+) Path Traversal via Backup Upload — Worry Proof Backup 8.8 High2026-02-26
CVE-2026-27969 Vitess users with backup storage access can write to arbitrary file paths on restore — vitess 6.5AIMediumAI2026-02-26
CVE-2026-1557 WP Responsive Images <= 1.0 - Unauthenticated Path Traversal to Arbitrary File Read via src — WP Responsive Images 7.5 High2026-02-26
CVE-2026-27884 NetExec vulnerable to arbitrary file write via path traversal in spider_plus module — NetExec 5.3 Medium2026-02-26
CVE-2026-27735 mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries — servers 8.6AIHighAI2026-02-25
CVE-2026-27800 Zed has Zip Slip Path Traversal in Extension Archive Extraction — zed 7.4 High2026-02-25
CVE-2026-27819 Vikunja has Path Traversal in CLI Restore — vikunja 7.2 High2026-02-25
CVE-2026-26985 LORIS vulnerable to path traversal in electrophysiology_browser — Loris 8.1 High2026-02-25
CVE-2026-26984 LORIS media module vulnerable to remote code execution — Loris 8.8AIHighAI2026-02-25
CVE-2026-3188 feiyuchuixue sz-boot-parent API templates path traversal — sz-boot-parent 4.3 Medium2026-02-25
CVE-2026-27704 Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction — sdk 7.3AIHighAI2026-02-25
CVE-2026-27699 Basic FTP has Path Traversal Vulnerability in its downloadToDir() method — basic-ftp 9.1 Critical2026-02-25
CVE-2026-25785 MOTEX LanScope Endpoint Manager 路径遍历漏洞 — Lanscope Endpoint Manager (On-Premises) Sub-Manager Server 8.8AIHighAI2026-02-25
CVE-2026-3179 A path traversal vulnerability was found in the FTP Backup on the ADM. — ADM 6.5 -2026-02-25
CVE-2026-27606 Rollup 4 has Arbitrary File Write via Path Traversal — rollup 9.9 -2026-02-25
CVE-2026-24849 OpenEMR Arbitrary File Read Vulnerability — openemr 10.0 Critical2026-02-25
CVE-2026-27598 Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory — dagu 8.8 -2026-02-25
CVE-2026-27117 bit7z has a path traversal vulnerability — bit7z 5.5 Medium2026-02-24
CVE-2026-25891 Fiber has an Arbitrary File Read in Static Middleware on Windows — fiber 7.5AIHighAI2026-02-24
CVE-2026-25603 Path Traversal vulnerability in Linksys MR9600, Linksys MX4200 — MR9600 6.8AIMediumAI2026-02-24
CVE-2026-27483 MindsDB has Path Traversal in /api/files Leading to Remote Code Execution — mindsdb 8.8 High2026-02-24
CVE-2025-15589 MuYuCMS Template Management Template.php delete_dir_file path traversal — MuYuCMS 3.8 Low2026-02-24
CVE-2026-3067 HummerRisk Archive Extraction CommandUtils.java extractZip path traversal — HummerRisk 6.3 Medium2026-02-24
CVE-2026-25965 ImageMagick's policy bypass through path traversal allows reading restricted content despite secured policy — ImageMagick 8.6 High2026-02-24

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3327 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.