Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3331

3331 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-10951 geyang ml-logger server.py log_handler path traversal — ml-logger 7.3 High2025-09-25
CVE-2025-10449 Path Traversal in Saysis Computer Systems' Saysis Web Portal — Saysis Web Portal 8.6 High2025-09-25
CVE-2025-59343 tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball — tar-fs 7.5AIHighAI2025-09-24
CVE-2025-59825 astral-tokio-tar has a path traversal in tar extraction — tokio-tar 7.5 -2025-09-23
CVE-2025-9963 Path Traversal — P series (P07, P10, P12, P15) 9.8AICriticalAI2025-09-23
CVE-2025-10777 JSC R7 R7-Office Document Server downloadas path traversal — R7-Office Document Server 6.3 Medium2025-09-22
CVE-2025-10766 SeriaWei ZKEACMS EventViewerController.cs Download path traversal — ZKEACMS 4.3 Medium2025-09-21
CVE-2025-9079 Admin RCE via prepackaged plugins by way of misconfigured imports directory — Mattermost 8.0 High2025-09-19
CVE-2025-10709 Four-Faith Water Conservancy Informatization Platform historyDownload.do;otheruserLogin.do;getfile path traversal — Water Conservancy Informatization Platform 5.3 Medium2025-09-19
CVE-2025-10708 Four-Faith Water Conservancy Informatization Platform historyDownload.do;usrlogout.do path traversal — Water Conservancy Informatization Platform 5.3 Medium2025-09-19
CVE-2025-10468 Path Traversal in Beyaz Computer's CityPLus — CityPlus 7.5 High2025-09-19
CVE-2025-59414 Nuxt Client-Side Path Traversal in Nuxt Island Payload Revival — nuxt 3.1 Low2025-09-17
CVE-2025-35430 CISA Thorium insecure downloaded file path validation — Thorium 5.0 Medium2025-09-17
CVE-2025-9215 StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.5.0 - Authenticated (Subscriber+) Arbitrary File Download — StoreEngine — Complete eCommerce Solution with Memberships, Licensing, Affiliates & More 6.5 Medium2025-09-17
CVE-2025-10050 Developer Loggers for Simple History <= 0.5 - Authenticated (Admin+) Local File Inclusion — Developer Loggers for Simple History 6.6 Medium2025-09-17
CVE-2025-59336 Relative Path Traversal in Luanox — luanox 9.1AICriticalAI2025-09-16
CVE-2025-59056 FreePBX vulnerable to unauthenticated Denial of Service — framework 3.8AILowAI2025-09-15
CVE-2025-10472 harry0703 MoneyPrinterTurbo URL video.py stream_video path traversal — MoneyPrinterTurbo 5.3 Medium2025-09-15
CVE-2025-10176 The Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File Deletion — The Hack Repair Guy's Plugin Archiver 7.2 High2025-09-12
CVE-2025-10273 erjinzhi 10OA file.aspx path traversal — 10OA 3.5 Low2025-09-11
CVE-2025-58320 DIALink - Directory Traversal Authentication Bypass Vulnerability — DIALink 7.3 High2025-09-11
CVE-2025-58321 DIALink - Directory Traversal Authentication Bypass Vulnerability — DIALink 10.0 Critical2025-09-11
CVE-2025-9918 Zip Slip in Google SecOps SOAR allows for Remote Code Execution — Google SecOps SOAR 8.8AIHighAI2025-09-11
CVE-2025-9693 User Meta – User Profile Builder and User management plugin <= 3.1.2 - Authenticated (Subscriber+) Arbitrary File Deletion — User Meta – User Profile Builder and User management plugin 8.0 High2025-09-11
CVE-2025-10245 Display Painéis TGA Galeria rename path traversal — TGA 4.3 Medium2025-09-11
CVE-2025-10236 binary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversal — gpt_academic 4.3 Medium2025-09-11
CVE-2025-10233 kalcaddle kodbox editor.class.php fileSave path traversal — kodbox 6.3 Medium2025-09-10
CVE-2025-10232 299ko FileManagerAPIController.php delete path traversal — 299ko 5.4 Medium2025-09-10
CVE-2025-41714 Path Traversal via 'Upload-Key' in SmartEMS Upload Handling — SmartEMS Web Application 8.8 High2025-09-10
CVE-2025-23343 NVIDIA NVDebug 路径遍历漏洞 — NVDebug tool 7.6 High2025-09-09

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3331 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.