Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-9435 Path Traversal — ManageEngine ADManager Plus 5.5 Medium2026-01-13
CVE-2025-68472 MindsDB has improper sanitation of filepath that leads to information disclosure and DOS — mindsdb 8.1 High2026-01-12
CVE-2025-69267 Spectrum directory path traversal — DX NetOps Spectrum 6.5AIMediumAI2026-01-12
CVE-2026-22685 DevToys Path Traversal (“Zip Slip”) Vulnerability in DevToys Extension Installation — DevToys 8.8 High2026-01-10
CVE-2025-61686 React Router has Path Traversal in File Session Storage — react-router 9.1 Critical2026-01-10
CVE-2025-66051 Path traversal in Vivotek IP7137 cameras — IP7137 8.1 -2026-01-09
CVE-2025-69194 Wget2: arbitrary file write via metalink path traversal in gnu wget2 8.8 High2026-01-09
CVE-2019-25295 WP Cost Estimation < 9.660 - Upload Directory Traversal — WP Cost Estimation & Payment Forms Builder 6.5 Medium2026-01-08
CVE-2017-20212 FLIR Thermal Camera F/FC/PT/D 8.0.0.64 Information Disclosure via File Reading — FLIR Thermal Camera F/FC/PT/D 6.2 Medium2026-01-07
CVE-2026-21851 MONAI has Path Traversal (Zip Slip) in NGC Private Bundle Download — MONAI 5.3 Medium2026-01-07
CVE-2025-68705 RustFS Path Traversal Vulnerability — rustfs 6.5 -2026-01-07
CVE-2026-0669 Path Traversal vulnerability in CSS extension on certain web servers — MediaWiki - CSS extension 7.5 -2026-01-07
CVE-2025-13801 Yoco Payments <= 3.9.0 - Unauthenticated Arbitrary File Read — Yoco Payments 7.5 High2026-01-07
CVE-2025-14867 Flashcard Plugin for WordPress <= 0.9 - Authenticated (Contributor+) Arbitrary File Read via Path Traversal — Flashcard Plugin for WordPress 6.5 Medium2026-01-07
CVE-2020-36909 Secure Computing SnapGear Management Console SG560 3.1.5 Arbitrary File Read/Write — SnapGear Management Console SG560 6.5 Medium2026-01-06
CVE-2025-14997 BuddyPress Xprofile Custom Field Types <= 1.2.8 - Authenticated (Subscriber+) Arbitrary File Deletion — BuddyPress Xprofile Custom Field Types 8.8 High2026-01-06
CVE-2026-0604 FastDup <= 2.7 - Authenticated (Contributor+) Path Traversal via 'dir_path' REST Parameter — FastDup – Fastest WordPress Migration & Duplicator 6.5 Medium2026-01-06
CVE-2025-69226 AIOHTTP allows for a brute-force leak of internal static filepath components — aiohttp 5.3 -2026-01-05
CVE-2025-68953 Certain Frappe requests are vulnerable to Path Traversal — frappe 7.5 High2026-01-05
CVE-2025-15449 cld378632668 JavaMall MinioController.java delete path traversal — JavaMall 5.4 Medium2026-01-05
CVE-2026-0571 yeqifu warehouse AppFileUtils.java createResponseEntity path traversal — warehouse 4.3 Medium2026-01-02
CVE-2026-21440 AdonisJS Path Traversal in Multipart File Handling — core 7.5 -2026-01-02
CVE-2025-59384 Qfiling — Qfiling 7.5 -2026-01-02
CVE-2025-59381 QTS, QuTS hero — QTS 4.9 -2026-01-02
CVE-2025-59380 QTS, QuTS hero — QTS 4.9 -2026-01-02
CVE-2025-53594 Qfinder Pro, Qsync, QVPN — Qfinder Pro Mac 5.5 -2026-01-02
CVE-2025-15432 yeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversal — carRental 5.3 Medium2026-01-02
CVE-2022-50796 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi — Impact/Pulse/First 9.8 Critical2025-12-30
CVE-2022-50792 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability — Impact/Pulse/First 7.5 High2025-12-30
CVE-2025-15245 D-Link DCS-850L Firmware Update Service uploadfirmware path traversal — DCS-850L 3.5 Low2025-12-30

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.