Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-24406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce 7.5 High2025-02-11
CVE-2024-36508 Fortinet FortiManager和Fortinet FortiAnalyzer 路径遍历漏洞 — FortiManager 5.9 Medium2025-02-11
CVE-2024-11771 Ivanti CSA 路径遍历漏洞 — Cloud Services Application 5.3 Medium2025-02-11
CVE-2025-25243 Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) — SAP Supplier Relationship Management (Master Data Management Catalog) 8.6 High2025-02-11
CVE-2024-8685 Path-Traversal vulnerability in Revolution Pi — Revolution Pi 4.3 Medium2025-02-10
CVE-2025-1106 CmsEasy database_admin.php restore_action path traversal — CmsEasy 5.4 Medium2025-02-07
CVE-2025-25163 WordPress Plugin A/B Image Optimizer Plugin <= 3.3 - Arbitrary File Download vulnerability — Plugin A/B Image Optimizer 7.5 High2025-02-07
CVE-2025-25155 WordPress Music Sheet Viewer plugin <= 4.1 - Arbitrary File Read vulnerability — Music Sheet Viewer 7.5 High2025-02-07
CVE-2025-0859 Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function — Post and Page Builder by BoldGrid – Visual Drag and Drop Editor 6.5 Medium2025-02-06
CVE-2025-0799 IBM App Connect Enterprise Arbitrary File Write — IBM App Connect Enterprise 6.5 Medium2025-02-06
CVE-2025-22601 Client Side Path Traversal using activate account route in Discourse — discourse 3.1 Low2025-02-04
CVE-2025-24963 Browser mode serves arbitrary files in vitest — vitest 5.9 Medium2025-02-04
CVE-2024-48019 Apache Doris: allows admin users to read arbitrary files through the REST API — Apache Doris 4.9 -2025-02-04
CVE-2025-24960 Missing Input validation for filename in backups endpoint in Jellystat — Jellystat 8.7 High2025-02-03
CVE-2025-24961 Insecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3Proxy — s3proxy 7.5 -2025-02-03
CVE-2025-24605 WordPress WOLF plugin <= 1.0.8.5 - Path Traversal vulnerability — WOLF 7.5 Medium2025-02-03
CVE-2025-24569 WordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.5 - Arbitrary File Read vulnerability — PDF Generator Addon for Elementor Page Builder 7.5 High2025-02-03
CVE-2025-23819 WordPress WP Cloud plugin <= 1.4.3 - Arbitrary File Deletion vulnerability — WP Cloud 7.5 High2025-02-03
CVE-2025-0973 CmsEasy index.php backAll_action path traversal — CmsEasy 5.4 Medium2025-02-03
CVE-2025-0365 Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read — Jupiter X Core 6.5 Medium2025-02-01
CVE-2025-24891 Dumb Drop has an arbitrary file overwrite and path traversal for root shell — DumbDrop 9.7 Critical2025-01-31
CVE-2025-0493 MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion — MultiVendorX – WooCommerce Multivendor Marketplace Solutions 9.8 Critical2025-01-31
CVE-2025-0572 Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability — PACS Server 6.5 -2025-01-30
CVE-2025-0573 Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability — PACS Server 7.5 -2025-01-30
CVE-2024-13671 Music Sheet Viewer <= 4.1 - Unauthenticated Arbitrary File Read — Music Sheet Viewer 7.5 High2025-01-30
CVE-2025-0750 Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting 6.6 Medium2025-01-28
CVE-2024-45598 Cacti has a Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path — cacti 6.0 Medium2025-01-27
CVE-2023-38012 IBM Cloud Pak System directory traversal — Cloud Pak System 5.3 Medium2025-01-25
CVE-2024-13550 ABC Notation <= 6.1.3 - Authenticated (Contributor+) Arbitrary File Read — ABC Notation 6.5 Medium2025-01-25
CVE-2024-12885 Connections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory Deletion — Connections Business Directory 6.5 Medium2025-01-25

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.