Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3330

3330 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1812 bolo-blog bolo-solo Filename BackupService.java importFromCnblogs path traversal — bolo-solo 6.3 Medium2026-02-03
CVE-2020-37088 School ERP Pro 1.0 - Arbitrary File Read — School ERP Pro 7.5 High2026-02-03
CVE-2020-37086 Easy Transfer 1.7 for iOS - Directory Traversal — Easy Transfer 6.2 Medium2026-02-03
CVE-2020-37077 Booked Scheduler 2.7.7 - Authenticated Directory Traversal — Booked Scheduler 6.5 Medium2026-02-03
CVE-2026-1811 bolo-blog bolo-solo Filename BackupService.java importFromMarkdown path traversal — bolo-solo 6.3 Medium2026-02-03
CVE-2026-24053 Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes — claude-code 6.5AIMediumAI2026-02-03
CVE-2025-65077 Relative path traversal vulnerability in Embedded Solutions Framework — MXTCT, MSNGM, MSTGM, MXNGM, MXTGM, CSNGV, CSTGV, CXTGV, MSNGW, MSTGW, MXTGW, CSTLS, CXTLS, MXTLS, CSTMM, CXTMM, CSTPC, CXTPC, MXTPM, MSNSN, MSTSN, MXTSN, CSNZJ, CSTZJ, CXNZJ, CXTZJ 9.8AICriticalAI2026-02-03
CVE-2026-1810 bolo-blog bolo-solo ZIP File BackupService.java unpackFilteredZip path traversal — bolo-solo 6.3 Medium2026-02-03
CVE-2026-25228 SignalK Server has Path Traversal leading to information disclosure — signalk-server 5.0 Medium2026-02-02
CVE-2026-25059 OpenList affected by Path Traversal in file copy and remove handlers — OpenList 8.8 High2026-02-02
CVE-2025-66480 Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction — im-server 9.8 Critical2026-02-02
CVE-2025-14914 IBM WebSphere Application Server Liberty Path Traversal — WebSphere Application Server Liberty 7.6 High2026-02-02
CVE-2026-1703 Limited path traversal when installing wheel archives — pip 7.7AIHighAI2026-02-02
CVE-2026-1186 Path Traversal in EAP Legislator — EAP Legislator 6.5AIMediumAI2026-02-02
CVE-2021-47921 Free Photo & Video Vault 0.0.2 Directory Traversal Vulnerability via Web Request — Free Photo & Video Vault - WiFi Transfe‪r 6.5 Medium2026-02-01
CVE-2022-50950 Webile 1.0.1 Directory Traversal Vulnerability via Web Application — Webile 6.5 Medium2026-02-01
CVE-2026-25069 SunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/Deletion — Pironman Dashboard (pm_dashboard) 9.8AICriticalAI2026-01-31
CVE-2020-37041 OpenCTI 3.3.1 - Directory Traversal — OpenCTI 7.5 High2026-01-30
CVE-2020-37034 HelloWeb 2.0 - Arbitrary File Download — HelloWeb 7.5 High2026-01-30
CVE-2026-25152 @backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator — backstage 5.3 Medium2026-01-30
CVE-2026-0805 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller — Crafty Controller 8.2 High2026-01-30
CVE-2026-0963 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller — Crafty Controller 9.9 Critical2026-01-30
CVE-2026-25116 Runtipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path Traversal — runtipi 7.6 High2026-01-29
CVE-2026-24846 malcontent's archive extraction could write outside extraction directory — malcontent 5.5 Medium2026-01-29
CVE-2026-24687 Umbraco.Forms has path traversal and file enumeration vulnerability in Linux/Mac — Umbraco.Forms.Issues 4.9AIMediumAI2026-01-29
CVE-2020-37015 Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal — Ruijie Networks Switch eWeb S29_RGOS 7.5 High2026-01-29
CVE-2026-1616 osim: Path Traversal via query parameters in Nginx configuration — osim 7.5 High2026-01-29
CVE-2026-1588 jishenghua jshERP installByPath install path traversal — jshERP 2.7 Low2026-01-29
CVE-2026-1549 jishenghua jshERP PluginController uploadPluginConfigFile path traversal — jshERP 4.3 Medium2026-01-28
CVE-2026-24897 Authenticated Remote Code Execution via Arbitrary File Upload — Erugo 10.0 Critical2026-01-28

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3330 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.