Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3344

3344 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-0401 1902756969 reggie CommonController.java download path traversal — reggie 5.3 Medium2025-01-12
CVE-2025-22152 Improper Path Validation Enables Path Traversal in Multiple Components in Atheos — Atheos 8.8 -2025-01-10
CVE-2024-11642 Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion — Post Grid Master — Post Grids & AJAX Filters 9.8 Critical2025-01-09
CVE-2025-22130 Soft Serve allows path traversal attacks — soft-serve 8.8 -2025-01-08
CVE-2024-9939 WordPress File Upload <= 4.24.13 - Unauthenticated Path Traversal to Arbitrary File Read in wfu_file_downloader.php — Iptanus File Upload 7.5 High2025-01-08
CVE-2024-10585 InfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File Reading — InfiniteWP Client 5.3 Medium2025-01-08
CVE-2023-52953 Huawei HarmonyOS 路径遍历漏洞 — HarmonyOS 6.2 Medium2025-01-08
CVE-2024-12429 ABB AC500 路径遍历漏洞 — AC500 V3 4.3 Medium2025-01-07
CVE-2025-21623 ClipBucket V5 Unauthenticated Template Directory Update to Denial-of-Service — clipbucket-v5 7.5 High2025-01-07
CVE-2025-21622 ClipBucket V5 Avatar URL Path Traversal to Arbitrary File Delete — clipbucket-v5 7.5 High2025-01-07
CVE-2024-12425 Path traversal leading to arbitrary .ttf file write — LibreOffice 6.2 -2025-01-07
CVE-2024-56286 WordPress Classic Addons – WPBakery Page Builder plugin <= 3.0 - Local File Inclusion vulnerability — Classic Addons – WPBakery Page Builder 7.5 High2025-01-07
CVE-2024-12152 MIPL WC Multisite Sync <= 1.1.5 - Unauthenticated Arbitrary File Download — MIPL Multistore Sync for WooCommerce. Sync Products, Stock and Orders. 7.5 High2025-01-07
CVE-2024-12849 Error Log Viewer By WP Guru <= 1.0.1.3 - Missing Authorization to Unauthenticated Arbitrary File Read — Error Log Viewer By WP Guru 7.5 High2025-01-07
CVE-2024-41765 IBM Engineering Lifecycle Optimization - Publishing directory traversal — Engineering Lifecycle Optimization Publishing 6.5 Medium2025-01-04
CVE-2024-56514 Karmada Tar Slips in CRDs archive extraction — karmada 8.8 -2025-01-03
CVE-2024-56248 WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Download vulnerability — WPMasterToolKit 4.9 Medium2025-01-02
CVE-2024-56198 path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability — path-sanitizer 7.5 -2024-12-31
CVE-2024-12105 WhatsUp Gold - SnmpExtendedActiveMonitor path traversal — WhatsUp Gold 6.5 Medium2024-12-31
CVE-2024-11944 iXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution Vulnerability — TrueNAS CORE 8.8 -2024-12-30
CVE-2024-12850 Database Backup and check Tables Automated With Scheduler 2024 <= 2.32 - Authenticated (Admin+) Arbitrary File Read — Database Backup and Table Integrity Check with Automated Scheduling 4.9 Medium2024-12-24
CVE-2024-41887 Arbitrary File Overwrite — XRN-420S 9.8 -2024-12-24
CVE-2024-53961 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 8.1 High2024-12-23
CVE-2024-55947 Gogs has a Path Traversal in file update API — gogs 8.8 -2024-12-23
CVE-2024-56331 Local File Inclusion (LFI) via Improper URL Handling in uptime-kuma's `Real-Browser` monitor — uptime-kuma 6.8 Medium2024-12-20
CVE-2024-12830 Arista NG Firewall custom_handler Directory Traversal Remote Code Execution Vulnerability — NG Firewall 9.8 -2024-12-20
CVE-2024-12793 PbootCMS IndexController.php path traversal — PbootCMS 4.3 Medium2024-12-19
CVE-2024-38819 VMware Spring Framework 安全漏洞 — Spring Framework 7.5 High2024-12-19
CVE-2024-21547 Browsershot 安全漏洞 — spatie/browsershot 7.5 High2024-12-18
CVE-2024-56142 Path Traversal in pghoard — pghoard 6.5 -2024-12-17

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3344 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.