Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-7327 Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read — Ozeki SMS Gateway 7.5 -2025-11-12
CVE-2025-11366 N-central Authentication bypass via path traversal — N-central 9.8 -2025-11-12
CVE-2025-11565 Schneider Electric PowerChute Serial Shutdown 安全漏洞 — PowerChute™ Serial Shutdown 6.8 -2025-11-12
CVE-2025-12382 Path Traversal Allows Remote Code Execution in AlgoSec Firewall Analyzer — Firewall Analyzer 8.8 -2025-11-12
CVE-2025-62449 Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability — Microsoft Visual Studio Code CoPilot Chat Extension 6.8 Medium2025-11-11
CVE-2025-60722 Microsoft OneDrive for Android Elevation of Privilege Vulnerability — OneDrive for Android 6.5 Medium2025-11-11
CVE-2025-11696 Studio 5000 ® Simulation Interface SSRF — Studio 5000® Simulation Interface™ 6.5 -2025-11-11
CVE-2025-42919 Information Disclosure vulnerability in SAP NetWeaver Application Server Java — SAP NetWeaver Application Server Java 5.3 Medium2025-11-11
CVE-2025-42894 Path Traversal vulnerability in SAP Business Connector — SAP Business Connector 6.8 Medium2025-11-11
CVE-2018-25124 PacsOne Server 6.6.2 DICOM Web Viewer Directory Traversal LFI — PacsOne Server 7.5 -2025-11-10
CVE-2025-12923 liweiyi ChestnutCMS download resourceDownload path traversal — ChestnutCMS 2.7 Low2025-11-10
CVE-2025-12922 OpenClinica Community Edition CRF Data Import ImportCRFData path traversal — Community Edition 6.3 Medium2025-11-10
CVE-2025-12092 CYAN Backup <= 2.5.4 - Authenticated (Admin+) Arbitrary File Deletion — CYAN Backup 6.5 Medium2025-11-08
CVE-2025-12000 WPFunnels <= 3.6.2 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal — WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell 6.5 Medium2025-11-08
CVE-2025-64485 CVAT: Mounted share file overwrite via crafted request — cvat 7.1 -2025-11-07
CVE-2025-64433 KubeVirt Arbitrary Container File Read — kubevirt 6.5 Medium2025-11-07
CVE-2025-7719 Smallworld SWMFS Arbitrary File Ops — Smallworld 8.8 -2025-11-07
CVE-2025-57712 Qsync Central — Qsync Central 7.5 -2025-11-07
CVE-2025-64346 archives: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — archives 9.8 -2025-11-07
CVE-2025-64184 Dosage vulnerable to Directory Traversal through crafted HTTP responses — dosage 8.8 High2025-11-07
CVE-2025-58423 Advantech DeviceOn/iEdge Path Traversal — DeviceOn/iEdge 8.8 High2025-11-06
CVE-2025-59171 Advantech DeviceOn/iEdge Path Traversal — DeviceOn/iEdge 7.5 High2025-11-06
CVE-2025-62630 Advantech DeviceOn/iEdge Path Traversal — DeviceOn/iEdge 8.8 High2025-11-06
CVE-2025-12490 Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability — pfSense 8.8 -2025-11-06
CVE-2025-34238 Advantech WebAccess/VPN < 1.1.5 Path Traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() — WebAccess/VPN 4.9 -2025-11-06
CVE-2025-22397 Dell iDRAC9和Dell iDRAC10 路径遍历漏洞 — Integrated Dell Remote Access Controller 9 14G Versions 6.7 Medium2025-11-06
CVE-2025-60242 WordPress Download Counter plugin <= 1.4 - Arbitrary File Download vulnerability — Download Counter 7.5 High2025-11-06
CVE-2025-20374 Cisco Unified Contact Center Express Arbitrary File Download Vulnerability — Cisco Unified Contact Center Express 4.9 Medium2025-11-05
CVE-2025-64108 Cursor's Sensitive File Modification can Lead to NTFS Path Quirks — cursor 8.8 High2025-11-04
CVE-2025-64107 Cursor is Vulnerable to Path Manipulation Using Backslashes on Windows — cursor 8.8 High2025-11-04

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.