Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3330

3330 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-15187 GreenCMS File DataController.class.php path traversal — GreenCMS 3.8 Low2025-12-29
CVE-2025-15066 Arbitrary File Download through Path Traversal in Innorix WP — Innorix WP 6.2 Medium2025-12-29
CVE-2025-15138 prasathmani TinyFileManager tinyfilemanager.php path traversal — TinyFileManager 4.7 Medium2025-12-28
CVE-2025-15076 Tenda CH22 public path traversal — CH22 7.3 High2025-12-25
CVE-2019-25258 LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities — LogicalDOC Enterprise 7.5 High2025-12-24
CVE-2019-25256 VideoFlow Digital Video Protection DVP 2.10 Authenticated Directory Traversal — Digital Video Protection DVP 6.5 Medium2025-12-24
CVE-2019-25246 Beward N100 H.264 VGA IP Camera M2.1.6 Authenticated File Disclosure — N100 H.264 VGA IP Camera 8.8 High2025-12-24
CVE-2018-25144 Microhard Systems IPn4G 1.1.0 Arbitrary File Access via Undocumented System Editor — Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Arbitrary File Attacks 8.4 High2025-12-24
CVE-2025-13699 MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability — MariaDB 9.8AICriticalAI2025-12-23
CVE-2025-13698 Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability — OPNsense 5.7AIMediumAI2025-12-23
CVE-2025-14413 Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability — Desktop 7.8AIHighAI2025-12-23
CVE-2025-14420 pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability — PDF Architect 7.8AIHighAI2025-12-23
CVE-2023-53962 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write — Impact/Pulse/First 7.5 High2025-12-22
CVE-2023-53979 MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities — MyBB 8.8 High2025-12-22
CVE-2025-68476 KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential — keda 6.5AIMediumAI2025-12-22
CVE-2025-11540 Sharp NP series 安全漏洞 — NP-P502HL-2, NP-P502WL-2, NP-P502HLG-2, NP-P502WLG, NP-P502H, NP-P502W, NP-P452H, NP-P452W, NP-P502HG, NP-P502WG, NP-P452HG, NP-P452WG, NP-P502H+, NP-P502W+, NP-CR5450H, NP-CR5450W, NP-P502HL, NP-P502WL, NP-P502HLG, NP-P502WLG, NP-P502HL+, NP-P502WL+, NP-CR5450HL, NP-CR5450WL, NP-UM352W, NP-UM352WG, NP-UM352W+ 7.5AIHighAI2025-12-22
CVE-2025-14965 1541492390c yougou-mall ResourceController.java delete path traversal — yougou-mall 5.5 Medium2025-12-19
CVE-2025-14910 Edimax BR-6208AC FTP Daemon Service handle_retr path traversal — BR-6208AC 4.3 Medium2025-12-19
CVE-2025-68279 Weblate has an arbitrary file read via symbolic links — weblate 7.7 High2025-12-18
CVE-2025-34452 Streama Subtitle Download Path Traversal and SSRF Leading to Arbitrary File Write — Streama 8.8AIHighAI2025-12-18
CVE-2025-67653 Advantech WebAccess/SCADA Path Traversal — WebAccess/SCADA 4.3 Medium2025-12-18
CVE-2025-14850 Advantech WebAccess/SCADA Improper Limitation of a Pathname to a Restricted Directory — WebAccess/SCADA 8.1 High2025-12-18
CVE-2023-53944 EasyPHP Webserver 14.1 Path Traversal via Directory Traversal Sequences — EasyPHP Webserver 6.5 Medium2025-12-18
CVE-2025-64235 WordPress Tuturn plugin < 3.6 - Arbitrary File Download vulnerability — Tuturn 6.5 Medium2025-12-18
CVE-2025-40898 Path traversal in Import Arc data archive functionality in Guardian/CMC before 25.5.0 — Guardian 8.1 High2025-12-18
CVE-2025-64230 WordPress Filr plugin <= 1.2.10 - Arbitrary File Deletion vulnerability — Filr 7.7 High2025-12-18
CVE-2025-54748 WordPress MapSVG Plugin < 8.6.12 - Arbitrary File Download Vulnerability — MapSVG 7.5AIHighAI2025-12-18
CVE-2023-53907 Bludit 3.13.1 Authenticated Arbitrary File Download via Backup Plugin — Backup Plugin 6.5 Medium2025-12-17
CVE-2025-68145 mcp-server-git has missing path validation when using --repository flag — servers 9.8AICriticalAI2025-12-17
CVE-2025-68143 mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations — servers 9.1AICriticalAI2025-12-17

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3330 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.