Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4982 Pagure: path traversal in view_issue_raw_file() 7.6 High2025-05-12
CVE-2025-4545 CTCMS Content Management System File Tpl.php del path traversal — Content Management System 5.4 Medium2025-05-11
CVE-2025-4530 feng_ha_ha/megagao ssm-erp/production_ssm File FileController.java handleFileDownload path traversal — ssm-erp 4.3 Medium2025-05-11
CVE-2025-4529 Seeyon Zhiyuan OA Web Application System ZIP File M3CoreController.class download path traversal — Zhiyuan OA Web Application System 4.3 Medium2025-05-11
CVE-2025-4511 vector4wang spring-boot-quick quick-img2txt Img2TxtController.java ResponseEntity path traversal — spring-boot-quick 6.3 Medium2025-05-10
CVE-2025-2158 WordPress Review Plugin: The Ultimate Solution for Building a Review Website <= 5.3.5 - Authenticated (Contributor+) Local File Inclusion via Post Custom Fields — WordPress Review Plugin: The Ultimate Solution for Building a Review Website 8.8 High2025-05-10
CVE-2025-3897 EUCookieLaw <= 2.7.2 - Unauthenticated Arbitrary File Read — EUCookieLaw 5.9 Medium2025-05-09
CVE-2025-4206 WordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File Deletion — Groundhogg — CRM, Newsletters, and Marketing Automation 7.2 High2025-05-09
CVE-2025-4377 Path traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.php — Pro Cloud Server 7.5AIHighAI2025-05-09
CVE-2024-6648 Path Traversal in AP Page Builder — AP Page Builder 7.5AIHighAI2025-05-08
CVE-2025-44021 OpenStack Ironic 安全漏洞 — Ironic 2.8 Low2025-05-08
CVE-2025-32820 SonicWALL SMA100 安全漏洞 — SMA100 8.1AIHighAI2025-05-07
CVE-2025-20187 Cisco SD-WAN Manager Software Arbitrary File Creation Vulnerability — Cisco Catalyst SD-WAN Manager 6.5 Medium2025-05-07
CVE-2025-22479 Dell Storage Manager 路径遍历漏洞 — Dell Storage Center - Dell Storage Manager 3.5 Low2025-05-06
CVE-2025-4329 74CMS index path traversal — 74CMS 4.3 Medium2025-05-06
CVE-2025-46559 Misskey Directory Traversal Vulnerability in AiScript via `Mk:api` — misskey 5.4 Medium2025-05-05
CVE-2024-11615 Envolve Plugin <= 1.0 - Unauthenticated Language File Deletion — Envolve Plugin 5.3 Medium2025-05-05
CVE-2024-55913 IBM Concert Software path traversal — Concert Software 5.3 Medium2025-05-02
CVE-2025-4186 Wangshen SecGate 3600 g=route_ispinfo_export_save path traversal — SecGate 3600 6.3 Medium2025-05-02
CVE-2025-4185 Wangshen SecGate 3600 g=obj_area_export_save path traversal — SecGate 3600 6.3 Medium2025-05-01
CVE-2025-4178 xiaowei1118 java_server File Upload API FoodController.java path traversal — java_server 5.4 Medium2025-05-01
CVE-2025-4175 AlanBinu007 Spring-Boot-Advanced-Projects Upload Profile API Endpoint UserProfileController.java uploadUserProfileImage path traversal — Spring-Boot-Advanced-Projects 6.3 Medium2025-05-01
CVE-2025-46565 Vite's server.fs.deny bypassed with /. for files under project root — vite 6.5AIMediumAI2025-05-01
CVE-2025-27409 Joplin Server Vulnerable to Path Traversal — joplin 7.5 High2025-04-30
CVE-2025-4078 Wangshen SecGate 3600 g=log_export_file path traversal — SecGate 3600 4.3 Medium2025-04-29
CVE-2025-27937 SIOS Technology Quick Agent 路径遍历漏洞 — Quick Agent V3 6.5 -2025-04-27
CVE-2025-26692 SIOS Technology Quick Agent 路径遍历漏洞 — Quick Agent V3 9.8 -2025-04-27
CVE-2025-1565 Mayosis Core <= 5.4.1 - Unauthenticated Arbitrary File Read — Mayosis Core 7.5 High2025-04-25
CVE-2025-3300 WPMasterToolKit (WPMTK) – All in one plugin <= 2.5.2 - Authenticated (Administrator+) to Arbitrary File Read and Write — WPMasterToolKit (WPMTK) – All in one plugin 7.2 High2025-04-24
CVE-2025-3065 Database Toolset <= 1.8.4 - Unauthenticated Arbitrary File Deletion — Database Toolset 9.1 Critical2025-04-24

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.