Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3334

3334 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-9217 Slider Revolution <= 6.7.36 - Authenticated (Contributor+) Arbitrary File Read via 'used_svg' and 'used_images' — Slider Revolution 6.5 Medium2025-08-29
CVE-2025-54029 WordPress WooCommerce csv import export Plugin <= 2.0.6 - Arbitrary File Deletion Vulnerability — WooCommerce csv import export 7.7 High2025-08-28
CVE-2025-53588 WordPress UPC/EAN/GTIN Code Generator Plugin <= 2.0.2 - Arbitrary File Deletion Vulnerability — UPC/EAN/GTIN Code Generator 7.7 High2025-08-28
CVE-2025-58072 DOS & CO SS1 路径遍历漏洞 — SS1 7.5 -2025-08-28
CVE-2025-54819 DOS & CO SS1 路径遍历漏洞 — SS1 8.1 -2025-08-28
CVE-2025-9345 File Manager, Code Editor, and Backup by Managefy <= 1.4.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Download — File Manager, Code Editor, and Backup by Managefy 4.9 Medium2025-08-28
CVE-2024-13982 SPON IP Network Intercom System rj_get_token.php Arbitrary File Read — SPON IP Network Broadcast System 9.1AICriticalAI2025-08-27
CVE-2025-20344 Cisco Nexus Dashboard Path Traversal Vulnerability — Cisco Nexus Dashboard 6.5 Medium2025-08-27
CVE-2025-53120 Securden Unified PAM Path Traversal In File Upload — Unified PAM 9.4 Critical2025-08-25
CVE-2025-9409 lostvip-com ruoyi-go CommonController.go DownloadUpload path traversal — ruoyi-go 4.3 Medium2025-08-25
CVE-2025-8562 Custom Query Shortcode <= 0.4.0 - Authenticated (Contributor+) Path Traversal via lens Parameter — Custom Query Shortcode 6.5 Medium2025-08-25
CVE-2025-9118 Dataform Path Traversal — Dataform 9.1AICriticalAI2025-08-25
CVE-2025-52450 Salesforce Tableau Server 安全漏洞 — Tableau Server 6.5AIMediumAI2025-08-22
CVE-2010-20109 Barracuda Spam & Virus Firewall "locale" Path Traversal — Spam & Virus Firewall 9.1AICriticalAI2025-08-21
CVE-2025-6465 Path traversal in image upload with preview overwrite — Mattermost 4.3 Medium2025-08-21
CVE-2025-57753 vite-plugin-static-copy files not included in `src` are accessible with a crafted request — vite-plugin-static-copy 7.5 -2025-08-21
CVE-2025-8023 Path Traversal in Template Upload Allows Uploading Files Outside Target Directory — Mattermost 6.8 Medium2025-08-21
CVE-2025-8895 WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy — WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress 9.8 Critical2025-08-21
CVE-2025-36530 Import Path Traversal Enables Unauthorized Unsigned Plugin Installation — Mattermost 6.8 Medium2025-08-21
CVE-2025-53505 Group Office 路径遍历漏洞 — Group-Office 7.5 -2025-08-21
CVE-2012-10061 Sockso Music Host Server <= 1.5 Path Traversal — Music Host Server 7.5AIHighAI2025-08-20
CVE-2025-54927 Schneider Electric EcoStruxure Power Monitoring Expert和EcoStruxure Power Operation AdvancedReporting and Dashboards Module 路径遍历漏洞 — EcoStruxure™ Power Monitoring Expert (PME) 4.9 Medium2025-08-20
CVE-2025-54926 Schneider Electric EcoStruxure Power Monitoring Expert和Schneider Electric EcoStruxure Power Operation 路径遍历漏洞 — EcoStruxure™ Power Monitoring Expert (PME) 7.2 High2025-08-20
CVE-2025-47650 WordPress Infility Global <= 2.15.09 - Arbitrary File Download vulnerability — Infility Global 6.5 Medium2025-08-20
CVE-2025-48158 WordPress BuddyPress XProfile Custom Image Field Plugin <= 3.0.1 - Arbitrary File Deletion Vulnerability — BuddyPress XProfile Custom Image Field 8.6 High2025-08-20
CVE-2025-54021 WordPress Simple File List plugin <= 6.1.14 - Arbitrary File Download vulnerability — Simple File List 7.5 High2025-08-20
CVE-2025-8141 Redirection for Contact Form 7 <= 3.2.4 - Unauthenticated Arbitrary File Deletion — Redirection for Contact Form 7 8.8 High2025-08-20
CVE-2025-55295 qBit Manage Path Traversal Vulnerability — qbit_manage 6.5 Medium2025-08-19
CVE-2025-55282 aiven-db-migrate allows Privilege Escalation via unrestricted search_path during migration — aiven-db-migrate 9.1 Critical2025-08-18
CVE-2025-55214 Copier safe template has filesystem write access outside destination path — copier 7.5AIHighAI2025-08-18

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3334 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.