Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-26753 WordPress VideoWhisper Live Streaming Integration plugin <= 6.2 - Arbitrary File Download vulnerability — Broadcast Live Video 7.5 High2025-02-25
CVE-2025-20051 Arbitrary file read via block duplication in Mattermost Boards — Mattermost 9.9 Critical2025-02-24
CVE-2025-25279 Arbitrary file read in Mattermost Boards via import & export board archive — Mattermost 9.9 Critical2025-02-24
CVE-2025-1543 iteachyou Dreamer CMS ueditor-1.4.3.3 path traversal — Dreamer CMS 4.3 Medium2025-02-21
CVE-2025-27098 Unwanted access to the entire file system vulnerability due to a missing check in `staticFiles` HTTP handler in graphql-mesh — graphql-mesh 5.8 Medium2025-02-20
CVE-2024-49780 IBM OpenPages path traversal — OpenPages with Watson 5.3 Medium2025-02-20
CVE-2025-27092 Path Traversal Vulnerability in GHOSTS Photo Retrieval Endpoint — GHOSTS 6.5 -2025-02-19
CVE-2025-24965 .krun_config.json symlink attack creates or overwrites file on the host in crun — crun 6.5 -2025-02-19
CVE-2025-26615 Path Traversal endpoint 'examples.php' parameter 'src' in WeGIA — WeGIA 10.0 Critical2025-02-18
CVE-2025-26616 Path Traversal endpoint 'exportar_dump.php' parameter 'file' in WeGIA — WeGIA 6.5 -2025-02-18
CVE-2025-22663 WordPress Paid Videochat Turnkey Site plugin <= 7.2.12 - Arbitrary File Deletion vulnerability — Paid Videochat Turnkey Site 8.6 High2025-02-18
CVE-2025-25284 Path Traversal and Local File Read via VRT (Virtual Format) in ZOO-Project WPS Implementation — ZOO-Project 6.2 -2025-02-18
CVE-2025-1035 Path Traversal in Komtera Technolgies' KLog Server — KLog Server 5.7 Medium2025-02-18
CVE-2024-13725 Keap Official Opt-in Forms <= 2.0.1 - Unauthenticated Limited Local File Inclusion — Keap Official Opt-in Forms 9.8 Critical2025-02-18
CVE-2025-25223 LuxSoft LuxCal Web Calendar 路径遍历漏洞 — The LuxCal Web Calendar 7.5 -2025-02-18
CVE-2025-26779 WordPress Keep Backup Daily plugin <= 2.1.0 - Arbitrary File Download vulnerability — Keep Backup Daily 4.9 Medium2025-02-16
CVE-2025-1357 Seventh D-Guard HTTP GET Request path traversal — D-Guard 4.3 Medium2025-02-16
CVE-2025-1336 CmsEasy image_admin.php deleteimg_action path traversal — CmsEasy 4.3 Medium2025-02-16
CVE-2025-1335 CmsEasy file_admin.php deleteimg_action path traversal — CmsEasy 4.3 Medium2025-02-16
CVE-2025-25295 Label Studio has a Path Traversal Vulnerability via image Field — label-studio 7.5 -2025-02-14
CVE-2024-56477 IBM Power Hardware Management Console directory traversal — Power Hardware Management Console 6.5 Medium2025-02-14
CVE-2025-1127 Combination Path Traversal and Concurrent Execution vulnerability exists within the embedded web server — CX, XC, CS, MS, MX, XM, et. al. 9.1 Critical2025-02-13
CVE-2025-24889 Path traversal in sd-log Qubes virtual machine — securedrop-client 4.5 Medium2025-02-13
CVE-2025-24888 Path traversal in SecureDrop Client API.download_reply() — securedrop-client 8.1 High2025-02-13
CVE-2024-47266 Synology Active Backup for Business 路径遍历漏洞 — Active Backup for Business 2.7 Low2025-02-13
CVE-2024-47264 Synology Active Backup for Business 路径遍历漏洞 — Active Backup for Business 4.9 Medium2025-02-13
CVE-2024-10763 Campress <= 1.35 - Unauthenticated Local File Inclusion — Campress 9.8 Critical2025-02-13
CVE-2025-1228 olajowon Loggrove Logfile Update page path traversal — Loggrove 4.3 Medium2025-02-12
CVE-2024-11343 Telerik Document Processing Path Traversal — Telerik Document Processing Libraries 8.3 High2025-02-12
CVE-2025-0332 Progress UI for WinForms decompression path traversal vulnerability — Progress® Telerik® UI for WinForms 7.8 High2025-02-12

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.