Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3334

3334 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-54387 IPX is Vulnerable to Path Traversal via Prefix Matching Bypass — ipx 6.8AIMediumAI2025-08-05
CVE-2025-54794 Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access — claude-code 9.1AICriticalAI2025-08-05
CVE-2025-54802 pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE) — pyload 9.8 Critical2025-08-05
CVE-2025-8522 givanz Vvvebjs node.js save.php path traversal — Vvvebjs 5.0 Medium2025-08-04
CVE-2025-8516 Kingdee Cloud-Starry-Sky Enterprise Edition IIS-K3CloudMiniApp FileUploadAction.class path traversal — Cloud-Starry-Sky Enterprise Edition 5.3 Medium2025-08-04
CVE-2025-7694 Woffice Core <= 5.4.26 - Authenticated (Contributor+) Arbitrary File Deletion — Woffice Core 6.8 Medium2025-08-02
CVE-2025-54386 Traefik's Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution — traefik 9.8 -2025-08-01
CVE-2013-10063 Netgear SPH200D <= 1.0.4.80 Path Traversal via HTTP GET — SPH200D 6.5 -2025-08-01
CVE-2013-10062 Linksys Routers apply.cgi Path Traversal — E1500 6.5 -2025-08-01
CVE-2013-10046 Agnitum Outpost Internet Security Local Privilege Escalation — Outpost Internet Security 8.4 -2025-08-01
CVE-2025-8480 Alpine iLX-507 Command Injection Remote Code Execution — iLX-507 8.8 -2025-08-01
CVE-2025-8433 code-projects Document Management System dell.php unlink path traversal — Document Management System 5.4 Medium2025-08-01
CVE-2025-8426 Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability — QConvergeConsole 9.1AICriticalAI2025-07-31
CVE-2014-125125 A10 Networks AX Loadbalancer Path Traversal — AX Series Loadbalancer 9.1AICriticalAI2025-07-31
CVE-2025-8151 HT Mega – Absolute Addons For Elementor <= 2.9.1 - Authenticated (Author+) Path Traversal to Limited Arbitrary CSS File Actions — HT Mega Addons for Elementor – Elementor Widgets & Template Builder 4.3 Medium2025-07-31
CVE-2025-41396 Alfasado PowerCMS 路径遍历漏洞 — PowerCMS 5.4 Medium2025-07-31
CVE-2025-46359 Alfasado PowerCMS 路径遍历漏洞 — PowerCMS 7.2 High2025-07-31
CVE-2025-8343 openviglet shio ShStaticFileAPI.java shStaticFilePreUpload path traversal — shio 4.3 Medium2025-07-31
CVE-2025-54433 Bugsink is vulnerable to Path Traversal attacks via event_id in ingestion — bugsink 8.3AIHighAI2025-07-30
CVE-2025-53081 SAMSUNG DMS 安全漏洞 — Data Management Server 6.4 Medium2025-07-29
CVE-2025-53080 SAMSUNG DMS 安全漏洞 — Data Management Server 7.1 High2025-07-29
CVE-2025-6989 Kallyas <= 4.21.0 - Authenticated (Contributor+) Arbitrary Folder Deletion — KALLYAS - Creative eCommerce Multi-Purpose WordPress Theme 8.1 High2025-07-26
CVE-2025-52452 Salesforce Tableau 安全漏洞 — Tableau Server 7.5 -2025-07-25
CVE-2025-8132 yanyutao0402 ChanCMS utils.js delfile path traversal — ChanCMS 5.4 Medium2025-07-25
CVE-2025-7640 hiWeb Export Posts <= 0.9.0.0 - Cross-Site Request Forgery to Arbitrary File Deletion — hiWeb Export Posts 8.1 High2025-07-24
CVE-2010-10012 httpdASM 0.92 Path Traversal — httpdasm 7.5 -2025-07-23
CVE-2018-25113 Dicoogle PACS Web Server 2.5.0 Unauthenticated Path Traversal — PACS Web Server 7.5 -2025-07-23
CVE-2025-54438 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-07-23
CVE-2025-54443 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-07-23
CVE-2025-54446 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-07-23

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3334 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.