Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-0703 JoeyBling bootplus SysFileController.java path traversal — bootplus 4.3 Medium2025-01-24
CVE-2025-24611 WordPress Export All Posts, Products, Orders, Refunds & Users Plugin <= 2.9 - Arbitrary File Read vulnerability — WP Ultimate Exporter 4.9 Medium2025-01-24
CVE-2024-13409 Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() — Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget 7.5 High2025-01-24
CVE-2025-23422 WordPress Store Locator plugin <= 3.98.10 - Local File Inclusion vulnerability — Store Locator 7.5 High2025-01-24
CVE-2024-13545 Bootstrap Ultimate <= 1.4.9 - Unauthenticated Limited Local File Inclusion — Bootstrap Ultimate 9.8 Critical2025-01-24
CVE-2024-42187 HCL BigFix Patch Download Plug-ins are affected by path traversal vulnerability — BigFix Patch Management Download Plug-ins 5.3 Medium2025-01-23
CVE-2025-23562 WordPress XLSXviewer plugin <= 2.1.1 - Arbitrary File Deletion vulnerability — XLSXviewer 7.5 Medium2025-01-22
CVE-2025-24019 YesWiki vulnerable to authenticated arbitrary file deletion — yeswiki 7.1 High2025-01-21
CVE-2025-0615 Input validation vulnerability in Qualifio's Wheel of Fortune — Wheel of fortune 5.3 Medium2025-01-21
CVE-2025-0614 Input validation vulnerability in Qualifio's Wheel of Fortune — Wheel of fortune 5.3 Medium2025-01-21
CVE-2024-45652 IBM Maximo Asset Management directory traversal — Maximo Asset Management 6.5 Medium2025-01-19
CVE-2024-10799 Eventer <= 3.9.7 - Authenticated (Subscriber+) Arbitrary File Read — Eventer - WordPress Event & Booking Manager Plugin 6.5 Medium2025-01-17
CVE-2024-52363 IBM InfoSphere Information Server directory traversal — InfoSphere Information Server 6.5 Medium2025-01-17
CVE-2024-48885 Fortinet多款产品 路径遍历漏洞 — FortiRecorder 5.2 Medium2025-01-16
CVE-2024-12087 Rsync: path traversal vulnerability in rsync 6.5 Medium2025-01-14
CVE-2024-12088 Rsync: --safe-links option bypass leads to path traversal 6.5 Medium2025-01-14
CVE-2024-13181 Ivanti Avalanche 安全漏洞 — Avalanche 7.3 High2025-01-14
CVE-2024-13180 Ivanti Avalanche 路径遍历漏洞 — Avalanche 7.5 High2025-01-14
CVE-2024-13179 Ivanti Avalanche 安全漏洞 — Avalanche 7.3 High2025-01-14
CVE-2025-0461 Shanghai Lingdang Information Technology Lingdang CRM index.php path traversal — Lingdang CRM 4.3 Medium2025-01-14
CVE-2024-39786 WAVLINK AC3000 路径遍历漏洞 — Wavlink AC3000 9.1 Critical2025-01-14
CVE-2024-39787 WAVLINK AC3000 路径遍历漏洞 — Wavlink AC3000 9.1 Critical2025-01-14
CVE-2024-33502 Fortinet FortiManager和FortiAnalyzer 路径遍历漏洞 — FortiManager 6.4 Medium2025-01-14
CVE-2024-47566 Fortinet FortiRecorder 路径遍历漏洞 — FortiRecorder 4.8 Medium2025-01-14
CVE-2024-48884 Fortinet多款产品 路径遍历漏洞 — FortiProxy 7.1 High2025-01-14
CVE-2024-36512 Fortinet FortiManager和FortiAnalyzer 路径遍历漏洞 — FortiManager 7.0 High2025-01-14
CVE-2024-12083 Path Traversal Vulnerabilities in NJ/NX-series Machine Automation Controllers — Machine Automation Controller NJ-series 6.6 Medium2025-01-14
CVE-2025-0401 1902756969 reggie CommonController.java download path traversal — reggie 5.3 Medium2025-01-12
CVE-2025-22152 Improper Path Validation Enables Path Traversal in Multiple Components in Atheos — Atheos 8.8 -2025-01-10
CVE-2024-11642 Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion — Post Grid Master — Post Grids & AJAX Filters 9.8 Critical2025-01-09

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.