Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-68143 mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations — servers 9.1AICriticalAI2025-12-17
CVE-2025-14727 NGINX Ingress Controller vulnerability — NGINX Ingress Controller 8.3 High2025-12-17
CVE-2025-12496 Zephyr Project Manager <= 3.3.203 - Authenticated (Custom+) Arbitrary File Read And Server-Side Request Forgery — Zephyr Project Manager 4.9 Medium2025-12-17
CVE-2025-68155 @vitejs/plugin-rsc has Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint on Development — vite-plugin-react 7.5 High2025-12-16
CVE-2023-53902 WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint — WebsiteBaker 6.5 Medium2025-12-16
CVE-2025-65076 Arbitrary File Read and Delete via Path Traversal in WaveStore Server — WaveStore Server 7.2AIHighAI2025-12-16
CVE-2025-65075 Arbitrary File Read and Delete via Path Traversal in WaveStore Server — WaveStore Server 7.2AIHighAI2025-12-16
CVE-2025-65074 OS Command Injection via Path Traversal in WaveStore Server — WaveStore Server 7.2AIHighAI2025-12-16
CVE-2025-66449 ConvertX has Path Traversal that leads to Arbitrary File Write and Arbitrary Code Execution — ConvertX 8.8 High2025-12-16
CVE-2025-34181 NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE — Manager 7.8AIHighAI2025-12-15
CVE-2025-14704 Shiguangwu sgwbox N3 API eshell path traversal — sgwbox N3 7.3 High2025-12-15
CVE-2025-14702 Smartbit CommV Smartschool App be.smartschool.mobile.SplashActivity path traversal — Smartschool App 4.4 Medium2025-12-15
CVE-2025-14699 Municorn FAX App biz.faxapp.app path traversal — FAX App 5.3 Medium2025-12-15
CVE-2025-14698 atlaszz AI Photo Team Galleryit App gallery.photogallery.pictures.vault.album path traversal — Galleryit App 4.4 Medium2025-12-15
CVE-2025-14617 Jehovahs Witnesses JW Library App org.jw.jwlibrary.mobile.activity.SiloContainer path traversal — JW Library App 5.3 Medium2025-12-13
CVE-2025-12960 Simple CSV Table <= 1.0.1 - Directory Traversal to Authenticated (Contributor+) Arbitrary File Read — Simple CSV Table 6.5 Medium2025-12-12
CVE-2025-13891 Image Gallery – Photo Grid & Video Gallery (Modula) <= 2.13.3 - Missing Authorization to Arbitrary Directory Listing — Modula Image Gallery – Photo Grid & Video Gallery 6.5 Medium2025-12-12
CVE-2025-12824 Player Leaderboard 1.0.0 - 1.0.2 - Authenticated (Contributor+) Local File Inclusion — Player Leaderboard 8.8 High2025-12-12
CVE-2025-14344 Multi Uploader for Gravity Forms <= 1.1.7 - Unauthenticated Arbitrary File Deletion — Multi Uploader for Gravity Forms 9.8 Critical2025-12-12
CVE-2025-13972 WatchTowerHQ <= 3.16.0 - Authenticated (Administrator+) Arbitrary File Read via 'wht_download_big_object_origin' Parameter — WatchTowerHQ 4.9 Medium2025-12-12
CVE-2024-58312 xbtitFM 4.1.18 Unauthenticated Path Traversal in nfogen.php — xbtitFM 7.5AIHighAI2025-12-11
CVE-2024-58310 APC Network Management Card 4 Path Traversal via Directory Traversal — Network Management Card 4 7.5AIHighAI2025-12-11
CVE-2025-14293 WP Job Portal <= 2.4.0 - Authenticated (Subscriber+) Arbitrary File Read — WP Job Portal – AI-Powered Recruitment System for Company or Job Board website 6.5 Medium2025-12-11
CVE-2025-14521 baowzh hfly download path traversal — hfly 4.3 Medium2025-12-11
CVE-2025-14520 baowzh hfly delfile path traversal — hfly 5.4 Medium2025-12-11
CVE-2025-67742 JetBrains TeamCity 路径遍历漏洞 — TeamCity 3.8 Low2025-12-11
CVE-2025-67720 Pyrofork has a Path Traversal in download_media Method — pyrofork 6.5 Medium2025-12-11
CVE-2020-36898 QiHang Media Web Digital Signage 3.0.9 Unauthenticated Arbitrary File Deletion — QiHang Media Web Digital Signage 9.1AICriticalAI2025-12-10
CVE-2020-36893 Eibiz i-Media Server Digital Signage 3.8.0 Directory Traversal Vulnerability — i-Media Server Digital Signage 7.5AIHighAI2025-12-10
CVE-2020-36883 SpinetiX Fusion Digital Signage 3.4.8 Authenticated Path Traversal via File Operations — Fusion Digital Signage 8.1AIHighAI2025-12-10

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.