Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-66302 Grav vulnerable to Path Traversal allowing server files backup — grav 6.8 Medium2025-12-01
CVE-2025-66300 Grav is vulnerable to Arbitrary File Read — grav 8.5 High2025-12-01
CVE-2025-66295 Grav vulnerable to Path traversal / arbitrary YAML write via user creation leading to Account Takeover / System Corruption — grav 8.8 High2025-12-01
CVE-2025-66206 Frappe vulnerable to a path traversal allowing reading certain files — frappe 6.8 Medium2025-12-01
CVE-2025-13816 moxi159753 Mogu Blog v2 ZIP File unzipFile FileOperation.unzip path traversal — Mogu Blog v2 6.3 Medium2025-12-01
CVE-2025-13810 jsnjfz WebStack-Guns KaptchaController.java renderPicture path traversal — WebStack-Guns 5.3 Medium2025-12-01
CVE-2025-13791 Scada-LTS Project Import ZIPProjectManager.java Common.getHomeDir path traversal — Scada-LTS 6.3 Medium2025-11-30
CVE-2025-12638 Path Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file() — keras-team/keras 9.1 -2025-11-28
CVE-2025-59890 Eaton Galileo 安全漏洞 — Eaton Galileo Software 7.3 High2025-11-27
CVE-2025-66262 Arbitrary File Overwrite via Tar Extraction Path Traversal — Mozart FM Transmitter 8.1AIHighAI2025-11-26
CVE-2025-66251 Unauthenticated Path Traversal with Arbitrary File Deletion — Mozart FM Transmitter 6.5AIMediumAI2025-11-26
CVE-2025-65952 Console is vulnerable to path traversal regarding custom assets — Console 6.5AIMediumAI2025-11-25
CVE-2025-34350 UnForm Server < 10.1.15 Doc Flow Unauthenticated File Read — UnForm Server 7.5AIHighAI2025-11-25
CVE-2025-59372 ASUS Router 安全漏洞 — Router 4.9AIMediumAI2025-11-25
CVE-2025-59366 ASUS Router 安全漏洞 — Router 9.8AICriticalAI2025-11-25
CVE-2025-34320 BASIS BBj < 25.00 Unauthenticated Arbitrary File Read RCE — BASIS BBj 9.1 -2025-11-20
CVE-2025-13435 Dreampie Resty HttpClient HttpClient.java request path traversal — Resty 5.6 Medium2025-11-20
CVE-2025-11001 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability — 7-Zip 8.8AIHighAI2025-11-19
CVE-2025-65025 esm.sh CDN service has arbitrary file write via tarslip — esm.sh 8.2 High2025-11-19
CVE-2025-64765 Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values — astro 8.2AIHighAI2025-11-19
CVE-2025-64757 Astro Development Server is Vulnerable to Arbitrary Local File Read — astro 3.5 Low2025-11-19
CVE-2025-40549 SolarWinds Serv-U Path Restriction Bypass Vulnerability — Serv-U 9.1 Critical2025-11-18
CVE-2025-13266 wwwlike vlife VLifeApi SysFileApi.java create path traversal — vlife 5.3 Medium2025-11-17
CVE-2025-13265 lsfusion platform ZipUtils.java unpackFile path traversal — platform 6.3 Medium2025-11-17
CVE-2025-13262 lsfusion platform UploadFileRequestHandler.java UploadFileRequestHandler path traversal — platform 7.3 High2025-11-17
CVE-2025-13261 lsfusion platform DownloadFileRequestHandler.java DownloadFileRequestHandler path traversal — platform 5.3 Medium2025-11-17
CVE-2025-13246 shsuishang ShopSuite ModulithShop JwtAuthenticationFilter.java JwtAuthenticationFilter path traversal — ShopSuite ModulithShop 6.3 Medium2025-11-16
CVE-2025-36236 AIX Path Traversal — AIX 8.2 High2025-11-13
CVE-2025-12089 Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion — Data Tables Generator by Supsystic 6.5 Medium2025-11-13
CVE-2016-15055 JVC VN-T IP-Camera Directory Traversal via check.cgi — IP-Camera (VN-T216VPRU) 7.5 -2025-11-12

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.