Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-25254 Fortinet FortiWeb 路径遍历漏洞 — FortiWeb 6.8 High2025-04-08
CVE-2024-41792 Siemens SENTRON 7KT PAC1260 Data Manager 路径遍历漏洞 — SENTRON 7KT PAC1260 Data Manager 8.6 High2025-04-08
CVE-2025-2519 Streamit <= 4.0.1 - Authenticated (Subscriber+) Arbitrary File Download — Streamit 6.5 Medium2025-04-08
CVE-2025-3381 zhangyanbo2007 youkefu File Upload WebIMController.java path traversal — youkefu 6.3 Medium2025-04-07
CVE-2025-3424 3.2.1 Arbitrary File Read in insecure .NET Remoting TCP Channel — IntelliSpace Portal 7.5AIHighAI2025-04-07
CVE-2025-31174 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.8 Medium2025-04-07
CVE-2025-3317 fumiao opencms dataPage.jsp path traversal — opencms 4.3 Medium2025-04-06
CVE-2025-2941 Drag and Drop Multiple File Upload for WooCommerce <= 1.1.4 - Unauthenticated Arbitrary File Move — Drag and Drop Multiple File Upload for WooCommerce 9.8 Critical2025-04-05
CVE-2025-3214 JFinal CMS readTemplate engine.getTemplate path traversal — CMS 4.3 Medium2025-04-04
CVE-2025-2270 Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion — Countdown, Coming Soon, Maintenance – Countdown & Clock 8.1 High2025-04-04
CVE-2025-31827 WordPress Fonto plugin <= 1.2.2 - Arbitrary File Download vulnerability — Fonto 4.9 Medium2025-04-03
CVE-2025-31825 WordPress Category Icon plugin <= 1.0.1 - Arbitrary File Download vulnerability — Category Icon 4.9 Medium2025-04-03
CVE-2025-31800 WordPress Publitio plugin <= 2.2.0 - Arbitrary File Read vulnerability — Publitio 6.5 Medium2025-04-03
CVE-2025-31554 WordPress Docxpresso plugin <= 2.6 - Arbitrary File Download vulnerability — Docxpresso 5.9 Medium2025-04-03
CVE-2025-30596 WordPress include-file plugin <= 1 - Arbitrary File Download Vulnerability — include-file 6.5 Medium2025-04-03
CVE-2025-30841 WordPress Countdown & Clock plugin <=2.8.8 - Remote Code Execution (RCE) vulnerability — Countdown & Clock 8.8 -2025-04-01
CVE-2025-31131 Path Traversal allowing arbitrary read of files in Yeswiki — yeswiki 8.6 High2025-04-01
CVE-2025-30910 WordPress CM Download Manager plugin <= 2.9.6 - Arbitrary File Deletion vulnerability — CM Download Manager 8.6 High2025-04-01
CVE-2025-30882 WordPress JS Help Desk plugin <= 2.9.1 - Arbitrary File Download vulnerability — JS Help Desk 7.5 High2025-04-01
CVE-2025-30878 WordPress JS Help Desk plugin <= 2.9.2 - Arbitrary File Deletion vulnerability — JS Help Desk 8.6 High2025-04-01
CVE-2025-30793 WordPress Houzez Property Feed plugin <= 2.5.4 - Arbitrary File Download Vulnerability — Houzez Property Feed 7.5 High2025-04-01
CVE-2025-30594 WordPress Include URL plugin <= 0.3.5 Arbitrary File Download Vulnerability — Include URL 6.5 Medium2025-04-01
CVE-2025-3043 GuoMinJim PersonManage login preHandle path traversal — PersonManage 5.3 Medium2025-04-01
CVE-2025-30005 Xorcom CompletePBX <= 5.2.35 Authenticated Path Traversal & File Deletion — CompletePBX 8.3 High2025-03-31
CVE-2025-2292 Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure — CompletePBX 6.5 Medium2025-03-31
CVE-2025-3021 Path Traversal vulnerability in e-management of e-solutions — e-management 7.5 -2025-03-31
CVE-2025-2917 ChestnutCMS read readFile path traversal — ChestnutCMS 4.3 Medium2025-03-28
CVE-2024-54291 WordPress PluginPass plugin <= 0.9.10 - Arbitrary File Download/Delete vulnerability — PluginPass 8.6 High2025-03-28
CVE-2025-27932 KDDI HGW BL1500HM 路径遍历漏洞 — HGW-BL1500HM 6.1 -2025-03-28
CVE-2025-27726 KDDI HGW BL1500HM 路径遍历漏洞 — HGW-BL1500HM 9.1 -2025-03-28

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.