Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3330

3330 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-1532 D-Link DCS-700L Music File Upload Service setUploadMusic uploadmusic path traversal — DCS-700L 2.4 Low2026-01-28
CVE-2020-36970 PMB 5.6 - 'chemin' Local File Disclosure — PMB Services 8.4 High2026-01-28
CVE-2026-1056 Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal — Snow Monkey Forms 9.8 Critical2026-01-28
CVE-2026-24842 node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal — node-tar 8.2 High2026-01-28
CVE-2026-24770 RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser — ragflow 9.8 Critical2026-01-27
CVE-2026-24741 ConvertX Vulnerable to Arbitrary File Deletion via Path Traversal in `POST /delete` — ConvertX 8.1 High2026-01-27
CVE-2020-36939 Cassandra Web 0.5.0 - Remote File Read — Cassandra Web 7.5 High2026-01-27
CVE-2026-24686 go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names — go-tuf 4.7 Medium2026-01-27
CVE-2026-24479 HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE — hustoj 8.8AIHighAI2026-01-27
CVE-2026-24486 Python-Multipart has Arbitrary File Write via Non-Default Configuration — python-multipart 8.6 High2026-01-27
CVE-2026-24478 AnythingLLM vulnerable to Path Traversal — anything-llm 7.2 High2026-01-26
CVE-2026-24123 BentoML has a Path Traversal via Bentofile Configuration — BentoML 7.4 High2026-01-26
CVE-2026-24131 pnpm has Path Traversal via arbitrary file permission modification — pnpm 7.7AIHighAI2026-01-26
CVE-2026-24056 pnpm has symlink traversal in file:/git dependencies — pnpm 7.7AIHighAI2026-01-26
CVE-2026-23889 pnpm has Windows-specific tarball Path Traversal — pnpm 6.5 Medium2026-01-26
CVE-2026-23888 pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip) — pnpm 6.5 Medium2026-01-26
CVE-2026-24469 C++ HTTP Server has Critical Path Traversal Vulnerability in RequestHandler Allowing Arbitrary File Read — http-server 7.5 High2026-01-24
CVE-2025-11002 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability — 7-Zip 8.8 -2026-01-23
CVE-2026-24137 sigstore legacy TUF client allows for arbitrary file writes with target cache path traversal — sigstore 5.8 Medium2026-01-23
CVE-2026-21227 Azure Logic Apps Elevation of Privilege Vulnerability — Azure Logic Apps 8.2 High2026-01-22
CVE-2026-23954 Incus container image templating arbitrary host file read and write — incus 8.7 High2026-01-22
CVE-2023-7335 EduSoho < 22.4.7 Arbitrary File Read via classroom-course-statistics — EduSoho 7.5AIHighAI2026-01-22
CVE-2025-69097 WordPress WPLMS plugin <= 1.9.9.5.4 - Arbitrary File Deletion vulnerability — WPLMS 8.6 High2026-01-22
CVE-2025-69055 WordPress BM Content Builder plugin < 3.16.3.3 - Arbitrary File Download vulnerability — BM Content Builder 6.5AIMediumAI2026-01-22
CVE-2025-68912 WordPress HDForms plugin <= 1.6.1 - Arbitrary File Deletion vulnerability — HDForms 8.6 High2026-01-22
CVE-2025-68907 WordPress Hostme v2 theme <= 7.0 - Arbitrary File Deletion vulnerability — Hostme v2 7.5 High2026-01-22
CVE-2025-68902 WordPress Anona theme <= 8.0 - Arbitrary File Download vulnerability — Anona 7.5 High2026-01-22
CVE-2025-68901 WordPress Anona theme <= 8.0 - Arbitrary File Deletion vulnerability — Anona 8.6 High2026-01-22
CVE-2025-67963 WordPress Movie Booking plugin <= 1.1.5 - Arbitrary File Deletion vulnerability — Movie Booking 7.5AIHighAI2026-01-22
CVE-2025-67684 Remote Code Execution via Local File Inclusion in Quick.Cart — Quick.Cart 7.2AIHighAI2026-01-22

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3330 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.