Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-5545 aaluoxiang oa_system ProcedureController.java image path traversal — oa_system 4.3 Medium2025-06-03
CVE-2025-5544 aaluoxiang oa_system UserpanelController.java image path traversal — oa_system 4.3 Medium2025-06-03
CVE-2025-5509 quequnlong shiyi-blog upload path traversal — shiyi-blog 6.3 Medium2025-06-03
CVE-2024-12718 Bypass extraction filter to modify file metadata outside extraction directory — CPython 5.3 Medium2025-06-03
CVE-2025-4138 Bypassing extraction filter to create symlinks to arbitrary targets outside extraction directory — CPython 7.5 High2025-06-03
CVE-2025-4330 Extraction filter bypass for linking outside extraction directory — CPython 7.5 High2025-06-03
CVE-2025-4517 Arbitrary writes via tarfile realpath overflow — CPython 9.4 Critical2025-06-03
CVE-2025-31359 Parallels Desktop 安全漏洞 — Parallels Desktop for Mac 8.8 High2025-06-03
CVE-2025-41428 Keiyo System TimeWorks 路径遍历漏洞 — TimeWorks 5.3AIMediumAI2025-06-03
CVE-2025-48387 tar-fs has issue where extract can write outside the specified dir with a specific tarball — tar-fs 6.5 -2025-06-02
CVE-2025-48940 MyBB's upgrade component vulnerable to local file inclusion — mybb 7.2 High2025-06-02
CVE-2025-33004 IBM Planning Analytics Local path traversal — Planning Analytics Local 6.5 Medium2025-06-01
CVE-2025-5385 JeeWMS cgformTemplateController.do doAdd path traversal — JeeWMS 6.3 Medium2025-05-31
CVE-2025-5381 Yifang CMS Admin Panel downloadFile path traversal — CMS 2.7 Low2025-05-31
CVE-2025-5380 ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 Image File Upload upload path traversal — XueShengZhuSu 学生住宿管理系统 6.3 Medium2025-05-31
CVE-2025-4857 Newsletters <= 4.9.9.9 - Authenticated (Administrator+) Local File Inclusion — Newsletters 7.2 High2025-05-31
CVE-2025-47952 Traefik allows path traversal using url encoding — traefik 9.1AICriticalAI2025-05-30
CVE-2025-5328 chshcms mccms Backups.php restore_del path traversal — mccms 5.4 Medium2025-05-29
CVE-2024-51453 IBM Sterling Secure Proxy directory traversal — Sterling Secure Proxy 4.3 Medium2025-05-28
CVE-2025-48744 SIGB PMB 路径遍历漏洞 — PMB 6.4 Medium2025-05-27
CVE-2025-5161 H3C SecCenter SMP-E1114P02 download operationDailyOut path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-26
CVE-2025-5160 H3C SecCenter SMP-E1114P02 download path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-26
CVE-2025-5159 H3C SecCenter SMP-E1114P02 download path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-25
CVE-2025-5158 H3C SecCenter SMP-E1114P02 downloadSoftware path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-25
CVE-2025-5157 H3C SecCenter SMP-E1114P02 fileContent path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-25
CVE-2025-31053 WordPress KBx Pro Ultimate plugin < 8.0.5 - Arbitrary File Deletion Vulnerability — KBx Pro Ultimate 7.7 High2025-05-23
CVE-2025-46486 WordPress Nomupay Payment Processing Gateway plugin <= 7.1.7 - Arbitrary File Download Vulnerability — Nomupay Payment Processing Gateway 4.9 Medium2025-05-23
CVE-2025-46527 WordPress Web3Press – Decentralize Publishing with Writing NFT plugin <= 3.2.0 - Arbitrary File Read vulnerability — Web3Press 6.5 Medium2025-05-23
CVE-2025-47492 WordPress Drag and Drop File Upload for Elementor Forms plugin <= 1.4.3 - Arbitrary File Deletion Vulnerability — Drag and Drop File Upload for Elementor Forms 8.6 High2025-05-23
CVE-2025-47513 WordPress Infocob CRM Forms plugin <= 2.4.0 - Arbitrary File Download vulnerability — Infocob CRM Forms 4.9 Medium2025-05-23

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.