Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3327

3327 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-23491 InvoicePlane has Unauthenticated Path Traversal in Guest Controller — InvoicePlane 7.5 -2026-02-18
CVE-2026-22860 Rack has a Directory Traversal via Rack:Directory — rack 7.5 High2026-02-18
CVE-2026-2464 Directory Traversal in AMR Printer Management by AMR — AMR Printer Management Beta web service 7.5AIHighAI2026-02-18
CVE-2026-2426 WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Deletion via 'file' Parameter — WP-DownloadManager 6.5 Medium2026-02-18
CVE-2026-2419 WP-DownloadManager <= 1.69 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'download_path' Parameter — WP-DownloadManager 2.7 Low2026-02-18
CVE-2026-2623 Blossom File Upload BLOSManager.java put path traversal — Blossom 6.3 Medium2026-02-17
CVE-2026-22762 Dell Avamar Server和Dell Avamar Virtual Edition 路径遍历漏洞 — Avamar Server 6.5 Medium2026-02-17
CVE-2025-36598 Dell Avamar 路径遍历漏洞 — Avamar Virtual Edition 6.5 Medium2026-02-17
CVE-2025-36597 Dell Avamar 路径遍历漏洞 — Avamar Server 4.7 Medium2026-02-17
CVE-2025-12062 WP Maps <= 4.8.6 - Authenticated (Subscriber+) Limited Local File Inclusion — WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters 8.8 High2026-02-16
CVE-2026-2552 ZenTao Editor control.php delete path traversal — ZenTao 5.5 Medium2026-02-16
CVE-2026-2551 ZenTao Backup control.php delete path traversal — ZenTao 5.4 Medium2026-02-16
CVE-2026-1793 Element Pack Addons for Elementor <= 8.3.17 - Authenticated (Contributor+) Arbitrary File Read — Element Pack – Widgets, Templates & Addons for Elementor 6.5 Medium2026-02-15
CVE-2025-13681 BFG Tools – Extension Zipper <= 1.0.7 - Authenticated (Administrator+) Path Traversal via 'first_file' Parameter — BFG Tools – Extension Zipper 4.9 Medium2026-02-14
CVE-2026-26187 lakeFS vulnerable to path traversal in local block adapter allow cross-namespace and sibling directory access — lakeFS 8.1 High2026-02-13
CVE-2026-25964 Tandoor Recipes Affected by Authenticated Local File Disclosure (LFD) via Recipe Import leads to Arbitrary File Read — recipes 4.9 Medium2026-02-13
CVE-2026-21878 BACnet Stack Improperly Limits Pathnames to a Restricted Directory — bacnet-stack 7.5 High2026-02-13
CVE-2019-25333 Bullwark Momentum Series JAWS 1.0 - 'Momentum Series JAWS' Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Momentum Series JAWS 7.5 High2026-02-12
CVE-2026-26217 Crawl4AI < 0.8.0 Docker API Local File Inclusion via file URL Handling — Crawl4AI 8.6 High2026-02-12
CVE-2025-15577 Valmet DNA Web server arbitrary file read access — Valmet DNA Web Tools 7.5AIHighAI2026-02-12
CVE-2020-37214 Voyager 1.3.0 - Directory Traversal — Voyager 7.5 High2026-02-11
CVE-2026-25062 Outline Affected an Arbitrary File Read via Path Traversal in JSON Import — outline 5.5 Medium2026-02-11
CVE-2026-25869 MiniGal Nano <= 0.3.5 Path Traversal via dir Parameter — MiniGal Nano 5.3AIMediumAI2026-02-11
CVE-2025-54162 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-58470 Qsync Central — Qsync Central 7.5AIHighAI2026-02-11
CVE-2025-62853 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-62855 File Station 5 — File Station 5 5.5AIMediumAI2026-02-11
CVE-2025-62856 File Station 5 — File Station 5 5.5AIMediumAI2026-02-11
CVE-2025-66278 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-68406 Qsync Central — Qsync Central 7.5AIHighAI2026-02-11

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3327 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.