Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3336

3336 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-54443 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-07-23
CVE-2025-54446 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 9.8 Critical2025-07-23
CVE-2025-54453 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 8.8 High2025-07-23
CVE-2025-54450 SAMSUNG MagicINFO 9 Server 安全漏洞 — MagicINFO 9 Server 7.2 High2025-07-23
CVE-2025-8021 Files Bucket Server 安全漏洞 — files-bucket-server 7.5 High2025-07-23
CVE-2025-54141 ViewVC's standalone server exposes arbitrary server filesystem content — viewvc 7.5 High2025-07-22
CVE-2025-54140 pyLoad has Path Traversal Vulnerability in json/upload Endpoint that allows Arbitrary File Write — pyload 7.5 High2025-07-22
CVE-2025-7645 Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) <= 3.2.8 - Unauthenticated Arbitrary File Deletion Triggered via Admin Form Submission Deletion — Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) 8.1 High2025-07-22
CVE-2025-49656 Apache Jena: Administrative users can create files outside the server directory space via the admin UI — Apache Jena 4.9 -2025-07-21
CVE-2025-7896 harry0703 MoneyPrinterTurbo video.py delete_video path traversal — MoneyPrinterTurbo 6.3 Medium2025-07-20
CVE-2015-10136 GI-Media Library < 3.0 - Directory Traversal — GI-Media Library 7.5 High2025-07-19
CVE-2015-10134 Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal — Simple Backup 7.5 High2025-07-19
CVE-2025-6233 Arbitrary file read by system admin via path traversal — Mattermost 6.8 Medium2025-07-18
CVE-2025-7643 Attachment Manager <= 2.1.2 - Unauthenticated Arbitrary File Deletion — Attachment Manager 9.1 Critical2025-07-18
CVE-2025-3740 School Management System for Wordpress <= 93.1.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password Update — School Management System for Wordpress 8.8 High2025-07-18
CVE-2025-7712 Madara - Core <= 2.2.3 - Unauthenticated Arbitrary File Deletion — Madara - Core 9.1 Critical2025-07-17
CVE-2025-34126 RIPS Scanner v0.54 Path Traversal — RIPS Scanner 7.5AIHighAI2025-07-16
CVE-2025-34120 LimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup Payload — LimeSurvey 7.5AIHighAI2025-07-16
CVE-2025-34118 Linknat VOS Manager Path Traversal File Disclosure — VOS Manager 7.5AIHighAI2025-07-16
CVE-2025-28955 WordPress Easy Video Player Wordpress & WooCommerce plugin <= 10.0 - Arbitrary File Download Vulnerability — Easy Video Player Wordpress & WooCommerce 7.5 High2025-07-16
CVE-2025-31070 WordPress HTML5 Radio Player - WPBakery Page Builder Addon plugin <= 2.5 - Arbitrary File Download vulnerability — HTML5 Radio Player - WPBakery Page Builder Addon 7.5 High2025-07-16
CVE-2025-7359 Counter live visitors for WooCommerce <= 1.3.6 - Unauthenticated Arbitrary File Deletion in wcvisitor_get_block — Counter live visitors for WooCommerce 8.2 High2025-07-16
CVE-2025-53906 Vim has path traversal issue with zip.vim and special crafted zip archives — vim 4.1 Medium2025-07-15
CVE-2025-53905 Vim has path traversial issue with tar.vim and special crafted tar files — vim 4.1 Medium2025-07-15
CVE-2025-49830 Conjur OSS and Secrets Manager, Self-Hosted (formerly Conjur Enterprise) vulnerable to path traversal and file disclosure — conjur 4.3AIMediumAI2025-07-15
CVE-2025-53622 DSpace has path traversal vulnerability in Simple Archive Format (SAF) package import via contents file — DSpace 5.2 Medium2025-07-15
CVE-2025-34110 ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure — Server 9.1AICriticalAI2025-07-15
CVE-2025-7360 HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. <= 2.2.1 - Directory Traversal to Arbitrary File Move — HT Contact Form – Drag & Drop Form Builder for WordPress 9.1 Critical2025-07-15
CVE-2025-6265 Zyxel NWA50AX PRO 路径遍历漏洞 — NWA50AX PRO firmware 7.2 High2025-07-15
CVE-2025-7628 YiJiuSmile kkFileViewOfficeEdit deleteFile path traversal — kkFileViewOfficeEdit 5.4 Medium2025-07-14

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3336 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.