Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3330

3330 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-62856 File Station 5 — File Station 5 5.5AIMediumAI2026-02-11
CVE-2025-66278 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2025-68406 Qsync Central — Qsync Central 7.5AIHighAI2026-02-11
CVE-2026-22894 File Station 5 — File Station 5 6.5AIMediumAI2026-02-11
CVE-2026-25872 JUNG Smart Panel 5.1 KNX Unauthenticated Path Traversal — JUNG Smart Panel 5.1 KNX 5.3 Medium2026-02-10
CVE-2026-25992 SiYuan has a File Read Interface Case Bypass Vulnerability — siyuan 7.5 High2026-02-10
CVE-2026-0651 Path Traversal on TP-Link Tapo D235 and C260 via Local https — Tapo C260 v1 6.1AIMediumAI2026-02-10
CVE-2025-12757 Axis Camera Station Pro 安全漏洞 — AXIS Camera Station Pro 4.6 Medium2026-02-10
CVE-2026-25895 FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API — FUXA 7.5AIHighAI2026-02-09
CVE-2026-25951 FUXA has a Path Traversal Sanitization Bypass — FUXA 7.2AIHighAI2026-02-09
CVE-2026-22905 Authentication Bypass via URI Traversal — 0852-1322 7.5 High2026-02-09
CVE-2026-2216 rachelos WeRSS we-mp-rss tools.py download_export_file path traversal — WeRSS we-mp-rss 4.3 Medium2026-02-09
CVE-2026-2111 JeecgBoot Retrieval-Augmented Generation edit path traversal — JeecgBoot 4.3 Medium2026-02-07
CVE-2026-25760 Website Path Traversal / Arbitrary File Read (Authenticated) in Sliver — sliver 6.5 Medium2026-02-06
CVE-2026-25732 NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write — nicegui 7.5 High2026-02-06
CVE-2026-25592 Semantic Kernel has an Arbitrary File Write via AI Agent Function Calling in .NET SDK — semantic-kernel 10.0 Critical2026-02-06
CVE-2026-25635 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution — calibre 8.6 High2026-02-06
CVE-2026-25636 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution — calibre 8.2 High2026-02-06
CVE-2026-25640 Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL — pydantic-ai 7.1 High2026-02-06
CVE-2026-24135 Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update — gogs 8.1AIHighAI2026-02-06
CVE-2026-23633 Gogs has arbitrary file read/write via path traversal in Git hook editing — gogs 6.5 Medium2026-02-06
CVE-2026-1523 Path Traversal in Digitek from Grupo Azkoyen — Digitek ADT1100 7.5AIHighAI2026-02-05
CVE-2026-1246 ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter — ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF 4.9 Medium2026-02-05
CVE-2026-25539 SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE — siyuan 9.1 Critical2026-02-04
CVE-2026-25161 Alist vulnerable to Path Traversal in multiple file operation handlers — alist 8.8 High2026-02-04
CVE-2026-25145 melange has a path traversal in license-path which allows reading files outside workspace — melange 5.5 Medium2026-02-04
CVE-2026-24843 melange QEMU runner could write files outside workspace directory — melange 8.2 High2026-02-04
CVE-2025-64712 Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write — unstructured 9.8 Critical2026-02-04
CVE-2026-25055 n8n Arbitrary File Write on Remote Systems via SSH Node — n8n 10.0AICriticalAI2026-02-04
CVE-2025-15487 Code Explorer <= 1.4.6 - Authenticated (Administrator+) Arbitrary File Read via 'file' Parameter — Code Explorer 4.9 Medium2026-02-04

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3330 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.