Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-27718 KDDI HGW BL1500HM 路径遍历漏洞 — HGW-BL1500HM 9.8 -2025-03-28
CVE-2025-27716 KDDI HGW BL1500HM 路径遍历漏洞 — HGW-BL1500HM 8.1 -2025-03-28
CVE-2025-2328 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.8.7 - Unauthenticated Arbitrary File Deletion — Drag and Drop Multiple File Upload for Contact Form 7 8.8 High2025-03-28
CVE-2025-2294 Kubio AI Page Builder <= 2.5.1 - Unauthenticated Local File Inclusion — Kubio AI Page Builder 9.8 Critical2025-03-28
CVE-2025-30895 WordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerability — WpEvently 7.5 High2025-03-27
CVE-2025-1769 Product Import Export for WooCommerce <= 2.5.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function — Product Import Export for WooCommerce – Import Export Product CSV Suite 4.9 Medium2025-03-26
CVE-2025-1310 Jobs for WordPress <= 2.7.11 - Authenticated (Subscriber+) Arbitrary File Read — Job Postings 6.5 Medium2025-03-26
CVE-2025-30567 WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability — WP01 7.5 High2025-03-25
CVE-2025-27147 GLPI Inventory plugin has Improper Access Control Vulnerability — glpi-inventory-plugin 8.2 High2025-03-25
CVE-2025-2744 zhijiantianya ruoyi-vue-pro Material Upload Interface upload-news-image path traversal — ruoyi-vue-pro 5.4 Medium2025-03-25
CVE-2025-2743 zhijiantianya ruoyi-vue-pro Material Upload Interface upload-temporary path traversal — ruoyi-vue-pro 4.3 Medium2025-03-25
CVE-2025-2742 zhijiantianya ruoyi-vue-pro Material Upload Interface upload-permanent path traversal — ruoyi-vue-pro 5.4 Medium2025-03-25
CVE-2025-2716 China Mobile P22g-CIac Samba Path path traversal — P22g-CIac 2.7 Low2025-03-24
CVE-2025-2708 zhijiantianya ruoyi-vue-pro Backend File Upload Interface upload path traversal — ruoyi-vue-pro 5.4 Medium2025-03-24
CVE-2025-2707 zhijiantianya ruoyi-vue-pro Front-End Store Interface upload path traversal — ruoyi-vue-pro 5.4 Medium2025-03-24
CVE-2025-2749 Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE — Xperience 7.2 High2025-03-24
CVE-2025-1973 Export and Import Users and Customers <= 2.6.2 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function — Export and Import Users and Customers 4.9 Medium2025-03-22
CVE-2024-13920 Order Export & Order Import for WooCommerce <= 2.6.0 - Directory Traversal to Authenticated (Administrator+) Limited Arbitrary File Read via download_file Function — Order Export & Order Import for WooCommerce 4.9 Medium2025-03-20
CVE-2024-12866 Local File Inclusion in netease-youdao/qanything — netease-youdao/qanything 9.8 -2025-03-20
CVE-2024-8769 Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim — aimhubio/aim 9.1 -2025-03-20
CVE-2024-10830 Path Traversal in eosphoros-ai/db-gpt — eosphoros-ai/db-gpt 9.1 -2025-03-20
CVE-2024-8524 Directory Traversal in modelscope/agentscope — modelscope/agentscope 7.5 -2025-03-20
CVE-2024-5752 Path Traversal in stitionai/devika — stitionai/devika 8.8 -2025-03-20
CVE-2024-12217 Path Traversal in gradio-app/gradio — gradio-app/gradio 3.3 -2025-03-20
CVE-2024-10948 Arbitrary File Read via Upload Function in binary-husky/gpt_academic — binary-husky/gpt_academic 6.5 -2025-03-20
CVE-2024-7776 Arbitrary File Overwrite in onnx/onnx — onnx/onnx 9.8 -2025-03-20
CVE-2024-8898 Path Traversal in parisneo/lollms-webui — parisneo/lollms-webui 9.1 -2025-03-20
CVE-2024-7034 Remote Code Execution due to Arbitrary File Write in open-webui/open-webui — open-webui/open-webui 9.1 -2025-03-20
CVE-2024-10707 Local File Inclusion in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 7.5 -2025-03-20
CVE-2024-6851 Arbitrary File Deletion in aimhubio/aim — aimhubio/aim 9.1 -2025-03-20

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.