Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-8438 Path Traversal in modelscope/agentscope — modelscope/agentscope 7.5 -2025-03-20
CVE-2024-12065 Local File Inclusion in haotian-liu/llava — haotian-liu/llava 7.5 -2025-03-20
CVE-2024-8060 Remote Code Execution in OpenWebUI via Arbitrary File Upload — open-webui/open-webui 8.8 -2025-03-20
CVE-2024-9362 Directory Traversal in polyaxon/polyaxon — polyaxon/polyaxon 7.5 -2025-03-20
CVE-2024-9597 Path Traversal in parisneo/lollms — parisneo/lollms 9.1 -2025-03-20
CVE-2024-8581 Path Traversal in parisneo/lollms-webui — parisneo/lollms-webui 7.5 -2025-03-20
CVE-2024-10902 Arbitrary File Upload with Path Traversal in eosphoros-ai/db-gpt — eosphoros-ai/db-gpt 9.8 -2025-03-20
CVE-2024-10361 Arbitrary File Deletion via Path Traversal in danny-avila/librechat — danny-avila/librechat 9.1 -2025-03-20
CVE-2024-9415 Path Traversal in transformeroptimus/superagi — transformeroptimus/superagi 9.8 -2025-03-20
CVE-2024-11037 Path Traversal in binary-husky/gpt_academic — binary-husky/gpt_academic 7.5 -2025-03-20
CVE-2025-2505 Age Gate <= 3.5.3 - Unauthenticated Local PHP File Inclusion via 'lang' — Age Gate 9.8 Critical2025-03-20
CVE-2025-1770 Event Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File Inclusion — Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) 8.8 High2025-03-20
CVE-2025-27782 Applio allows arbitrary file write in inference.py — Applio 9.8 -2025-03-19
CVE-2025-27783 Applio allows arbitrary file write in train.py — Applio 9.8 -2025-03-19
CVE-2025-27786 Applio allows arbitrary file removal in core.py — Applio 7.5 -2025-03-19
CVE-2024-7631 Openshift-console: openshift console: path traversal 4.3 Medium2025-03-19
CVE-2025-2449 NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability — FlexLogger 7.8 -2025-03-18
CVE-2025-2493 Path Traversal vulnerability in Softdial Contact Center — Softdial Contact Center 7.5 -2025-03-18
CVE-2025-0694 CODESYS Control V3 removable media path traversal — CODESYS Control for BeagleBone SL 6.6 Medium2025-03-18
CVE-2024-8510 N-central Path Traversal — N-central 5.3 Medium2025-03-17
CVE-2025-29787 zip Vulnerable to Incorrect Path Canonicalization During Archive Extraction, Leading to Arbitrary File Write — zip2 9.1 -2025-03-17
CVE-2025-2363 lenve VBlog ArticleController.java uploadImg path traversal — VBlog 6.3 Medium2025-03-17
CVE-2024-30143 A path traversal vulnerability in HCL AppScan Traffic Recorder — HCL AppScan Traffic Recorder 4.3 Medium2025-03-13
CVE-2025-2264 Santesoft Sante PACS Server Path Traversal Information Disclosure — Sante PACS Server 7.5 High2025-03-13
CVE-2025-1785 Download Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File Overwrite — Download Manager 5.4 Medium2025-03-13
CVE-2025-2215 Doufox s=doudou path traversal — Doufox 4.7 Medium2025-03-11
CVE-2025-27101 Broken Access Control in Opal filesystem's copy functionality exposes all user data — opal 6.5 -2025-03-11
CVE-2024-55597 Fortinet FortiWeb 路径遍历漏洞 — FortiWeb 5.2 Medium2025-03-11
CVE-2025-2193 MRCMS org.marker.mushroom.controller.FileController delete.do delete path traversal — MRCMS 5.4 Medium2025-03-11
CVE-2025-27397 Siemens SCALANCE LPE9403 路径遍历漏洞 — SCALANCE LPE9403 3.8 Low2025-03-11

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.