Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-34028 Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal — Command Center Innovation Release 9.8 -2025-04-22
CVE-2025-23250 NVIDIA Nemo Framework 路径遍历漏洞 — NeMo Framework 7.6 High2025-04-22
CVE-2025-3577 Zyxel AMG1302-T10B 安全漏洞 — AMG1302-T10B firmware 4.9 Medium2025-04-22
CVE-2025-32431 Traefik has a possible vulnerability with the path matchers — traefik 5.9 -2025-04-21
CVE-2025-3404 Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion — Download Manager 8.8 High2025-04-19
CVE-2025-3520 Avatar <= 0.1.4 - Authenticated (Subscriber+) Arbitrary File Deletion — Avatar 8.1 High2025-04-18
CVE-2025-27283 WordPress Theme File Duplicator Plugin <= 1.3 - Arbitrary File Download vulnerability — Theme File Duplicator 6.5 Medium2025-04-17
CVE-2025-27299 WordPress MyTicket Events plugin <= 1.2.4 - Non-Arbitrary File Read vulnerability — MyTicket Events 5.3 Medium2025-04-17
CVE-2025-39568 WordPress StoreContrl Woocommerce plugin <= 4.1.3 - Arbitrary File Download Vulnerability — StoreContrl Woocommerce 7.5 High2025-04-17
CVE-2025-3294 WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update — WP Editor 7.2 High2025-04-17
CVE-2025-3295 WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read — WP Editor 4.9 Medium2025-04-17
CVE-2025-3686 misstt123 oasys show image path traversal — oasys 4.3 Medium2025-04-16
CVE-2025-32779 labsai/eddi Vulnerable to Path Traversal (Zip Slip) in ZIP Import Function — EDDI 6.5 Medium2025-04-15
CVE-2025-32943 PeerTube HLS Video Files Path Traversal 3.7 Low2025-04-15
CVE-2025-3562 Yonyou YonBIP userfile FileInputStream path traversal — YonBIP 4.3 Medium2025-04-14
CVE-2025-3547 frdel Agent-Zero get_work_dir_files path traversal — Agent-Zero 6.3 Medium2025-04-14
CVE-2025-3445 archiver 路径遍历漏洞 — github.com/mholt/archiver/v3 8.1 High2025-04-13
CVE-2025-32671 WordPress Print Science Designer plugin <= 1.3.155 - Arbitrary File Download vulnerability — Print Science Designer 7.5 High2025-04-11
CVE-2025-32633 WordPress Database Toolset Plugin <= 1.8.4 - Arbitrary File Deletion vulnerability — Database Toolset 8.6 High2025-04-11
CVE-2025-32631 WordPress Oxygen MyData for WooCommerce plugin <= 1.0.64 - Arbitrary File Deletion vulnerability — Oxygen MyData for WooCommerce 8.6 High2025-04-11
CVE-2025-32629 WordPress WP-BusinessDirectory Plugin <= 3.1.2 - Arbitrary File Deletion vulnerability — WP-BusinessDirectory 8.6 High2025-04-11
CVE-2025-32587 WordPress WooCommerce Pickupp plugin <= 2.4.3 - Local File Inclusion vulnerability — WooCommerce Pickupp 8.1 High2025-04-11
CVE-2025-32509 WordPress Simple WP Events plugin <= 1.8.17 - Arbitrary File Deletion vulnerability — Simple WP Events 7.5 High2025-04-11
CVE-2025-2636 InstaWP Connect <= 0.1.0.85 - Unauthenticated Local PHP File Inclusion — InstaWP Connect – 1-click WP Staging & Migration 8.1 High2025-04-11
CVE-2025-31411 WordPress Linet ERP-Woocommerce Integration plugin <= 3.5.12 - Arbitrary File Read/Deletion vulnerability — Linet ERP-Woocommerce Integration 5.9 Medium2025-04-10
CVE-2025-32209 WordPress Total processing card payments for WooCommerce Plugin <= 7.1.5 - Arbitrary File Download vulnerability — Nomupay Payment Processing Gateway 6.5 Medium2025-04-10
CVE-2025-32205 WordPress Piotnet Forms plugin <= 1.0.30 - Path Traversal vulnerability — Piotnet Forms 6.5AIMediumAI2025-04-10
CVE-2025-30582 WordPress DyaPress ERP/CRM plugin <= 18.0.2.0 - Local File Inclusion Vulnerability — DyaPress ERP/CRM 8.1 High2025-04-10
CVE-2025-30290 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 8.7 High2025-04-08
CVE-2025-32018 Arbitrary file write from Cursor Agent through a prompt injection from malicious @Docs — cursor 8.1 High2025-04-08

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.