Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-7926 ZZCMS about_edit.php path traversal — ZZCMS 7.3 High2024-08-19
CVE-2024-43345 WordPress Landing Page Builder plugin <= 1.5.2.0 - Local File Inclusion vulnerability — Landing Page Builder 7.5 High2024-08-19
CVE-2024-43328 WordPress EmbedPress plugin <= 4.0.9 - Local File Inclusion vulnerability — EmbedPress 8.3 High2024-08-19
CVE-2024-7924 ZZCMS list.php path traversal — ZZCMS 5.3 Medium2024-08-19
CVE-2024-43281 WordPress Void Elementor Post Grid Addon for Elementor Page builder plugin <= 2.3 - Local File Inclusion vulnerability — Void Elementor Post Grid Addon for Elementor Page builder 5.3 Medium2024-08-19
CVE-2024-43271 WordPress Widgets for WooCommerce Products on Elementor plugin <= 2.0.0 - Local File Inclusion vulnerability — Woo Products Widgets For Elementor 8.5 High2024-08-19
CVE-2024-43248 WordPress Bit Form Pro plugin <= 2.6.4 - Unauthenticated Arbitrary File Deletion vulnerability — Bit Form Pro 8.6 High2024-08-19
CVE-2024-43232 WordPress Timeline and History slider plugin <= 2.3 - Local File Inclusion vulnerability — Timeline and History slider 8.5 High2024-08-19
CVE-2024-43221 WordPress JetGridBuilder plugin <= 1.1.2 - Local File Inclusion vulnerability — JetGridBuilder 8.5 High2024-08-19
CVE-2023-5505 BackWPup <= 4.0.1 - Authenticated (Administrator+) Directory Traversal — BackWPup – WordPress Backup & Restore Plugin 6.8 Medium2024-08-17
CVE-2024-43395 CraftOS-PC 2's improperly sanitizied paths cause filesystem escape (Windows) — craftos2 8.2 High2024-08-16
CVE-2024-7145 JetElements <= 2.6.20 - Authenticated (Contributor+) Arbitrary Local File Inclusion — JetElements 8.8 High2024-08-16
CVE-2024-7146 JetTabs <= 2.2.3 - Authenticated (Contributor+) Arbitrary Local File Inclusion — JetTabs 8.8 High2024-08-16
CVE-2024-7263 Arbitrary Code Execution in WPS Office — WPS Office 7.8AIHighAI2024-08-15
CVE-2024-7262 Arbitrary Code Execution in WPS Office — WPS Office 7.1AIHighAI2024-08-15
CVE-2024-39399 [Paris] Path Traversal lead to local file read — Adobe Commerce 7.7 High2024-08-14
CVE-2024-39406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce 6.8 Medium2024-08-14
CVE-2024-7741 wanglongcn ltcms API Endpoint downloadfile downloadFile path traversal — ltcms 5.3 Medium2024-08-13
CVE-2024-6618 Path Traversal in Ocean Data Systems Dream Report — Dream Report 2023 8.4AIHighAI2024-08-13
CVE-2024-43165 WordPress WPSection plugin <= 1.3.8 - Contributor+ Limited Local File Inclusion vulnerability — WPSection 6.5 Medium2024-08-13
CVE-2024-43140 WordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.4 - Local File Inclusion vulnerability — Ultimate Bootstrap Elements for Elementor 7.5 High2024-08-13
CVE-2024-43138 WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.2.1 - Local File Inclusion vulnerability — Event Manager for WooCommerce 6.5 Medium2024-08-13
CVE-2024-43135 WordPress WPCafe plugin <= 2.2.28 - Local File Inclusion vulnerability — WPCafe 7.5 High2024-08-13
CVE-2024-43129 WordPress BetterDocs plugin <= 3.5.8 - Local File Inclusion vulnerability — BetterDocs 6.5 Medium2024-08-13
CVE-2024-39651 WordPress WooCommerce PDF Vouchers plugin < 4.9.5 - Unauthenticated Arbitrary File Deletion vulnerability — WooCommerce PDF Vouchers 8.6 High2024-08-13
CVE-2024-41938 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 5.5 Medium2024-08-13
CVE-2024-42474 Streamlit Path Traversal Security Vulnerability on Windows — streamlit 7.5AIHighAI2024-08-12
CVE-2023-7249 OpenText Directory Services 安全漏洞 — OpenText Directory Services 6.5AIMediumAI2024-08-12
CVE-2024-42485 Filament Excel Vulnerable to Path Traversal Attack on Export Download Endpoint — filament-excel 7.5 High2024-08-12
CVE-2024-21876 Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225 — IQ Gateway 8.2AIHighAI2024-08-10

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.