Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-11849 Mammoth 安全漏洞 — mammoth 9.3 Critical2025-10-17
CVE-2025-34517 Ilevia EVE X1 Server 4.7.18.0.eden Absolute Path Traversal — EVE X1 Server 7.5AIHighAI2025-10-16
CVE-2025-34518 Ilevia EVE X1 Server 4.7.18.0.eden Relative Path Traversal — EVE X1 Server 7.5AIHighAI2025-10-16
CVE-2025-61923 PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure — ps_checkout 4.1 Medium2025-10-16
CVE-2025-11842 Shazwazza Smidge Bundle path traversal — Smidge 6.3 Medium2025-10-16
CVE-2025-53951 Fortinet FortiDLP 路径遍历漏洞 — FortiDLP 4.9 Medium2025-10-16
CVE-2025-54658 Fortinet FortiDLP 路径遍历漏洞 — FortiDLP 7.2 High2025-10-16
CVE-2025-54755 BIG-IP Configuration utility vulnerability — BIG-IP 4.9 Medium2025-10-15
CVE-2025-61941 BUFFALO WXR9300BE6P Series 路径遍历漏洞 — WXR9300BE6P series 7.2AIHighAI2025-10-15
CVE-2025-11746 XStore | Multipurpose WooCommerce Theme <= 9.5.4 - Authenticated (Subscriber+) Local File Inclusion — XStore 8.8 High2025-10-15
CVE-2024-13991 Huijietong Cloud Video Platform fileDownload Arbitrary File Read — Cloud Video Platform 7.5AIHighAI2025-10-15
CVE-2025-62156 argo-workflows Zip Slip path traversal allows arbitrary file write and container configuration overwrite — argo-workflows 8.1 High2025-10-14
CVE-2025-10986 Ivanti EPMM 路径遍历漏洞 — Endpoint Manager Mobile 4.7 Medium2025-10-14
CVE-2025-42906 Directory Traversal vulnerability in SAP Commerce Cloud — SAP Commerce Cloud 5.3 Medium2025-10-14
CVE-2025-9713 Ivanti Endpoint Manager 路径遍历漏洞 — Endpoint Manager 8.8 High2025-10-13
CVE-2025-11631 RainyGao DocSys deleteDoc.do path traversal — DocSys 5.4 Medium2025-10-12
CVE-2025-11630 RainyGao DocSys File Upload uploadDoc.do updateRealDoc path traversal — DocSys 6.3 Medium2025-10-12
CVE-2025-11607 harry0703 MoneyPrinterTurbo API Endpoint music.py upload_music path traversal — MoneyPrinterTurbo 6.3 Medium2025-10-11
CVE-2025-9950 Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read — Error Log Viewer by BestWebSoft 4.9 Medium2025-10-11
CVE-2025-6439 WooCommerce Designer Pro <= 1.9.26 - Unauthenticated Arbitrary File Deletion — WooCommerce Designer Pro 9.8 Critical2025-10-11
CVE-2025-34248 D-Link Nuclias Connect < v1.3.1.4 Directory Traversal to Arbitrary File Deletion — Nuclias Connect 8.1AIHighAI2025-10-09
CVE-2025-35056 Newforma Info Exchange (NIX) limited file read — Project Center 5.0 Medium2025-10-09
CVE-2025-35055 Newforma Info Exchange (NIX) insecure file upload — Project Center 8.8 High2025-10-09
CVE-2025-35053 Newforma Info Exchange (NIX) arbitrary file read and delete — Project Center 6.4 Medium2025-10-09
CVE-2025-10284 Improper Archive Extraction in unarchive Enables RCE — bbot 9.6 Critical2025-10-09
CVE-2025-10283 Improper .git Sanitization in gitdumper Enables RCE — bbot 9.6 Critical2025-10-09
CVE-2025-39664 Path-Traversal in report scheduler — Checkmk 4.3AIMediumAI2025-10-09
CVE-2025-7526 WP Travel Engine – Tour Booking Plugin – Tour Operator Software <= 6.6.7 - Authenticated (Subscriber+) Arbitrary File Deletion via File Renaming — WP Travel Engine – Tour Booking Plugin – Tour Operator Software 9.8 Critical2025-10-09
CVE-2025-61913 Flowise is vulnerable to arbitrary file read, arbitrary file write — Flowise 10.0 Critical2025-10-08
CVE-2025-61784 LLaMA Factory's Chat API has Critical SSRF and LFI Vulnerabilities — LLaMA-Factory 7.6 High2025-10-07

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.