Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-21877 Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225 — Envoy 8.1AIHighAI2024-08-10
CVE-2024-42469 CometVisu Backend for openHAB affected by RCE through path traversal — openhab-webui 9.8 Critical2024-08-09
CVE-2024-42468 Path traversal (CometVisu) — openhab-webui 5.3 Medium2024-08-09
CVE-2024-7399 SAMSUNG MagicINFO 安全漏洞 — MagicINFO 9 Server 8.8 High2024-08-09
CVE-2024-41936 Vonets WiFi Bridges Path Traversal — VAR1200-H 7.5 High2024-08-08
CVE-2024-42408 Dorsett Controls InfoScan Path Traversal — InfoScan 5.3 Medium2024-08-08
CVE-2024-6707 Open WebUI Arbitrary File Upload + Path Traversal — Open WebUI 9.8AICriticalAI2024-08-07
CVE-2024-7061 Okta Verify 安全漏洞 — Okta Verify for Windows 5.5 Medium2024-08-07
CVE-2024-7564 Logsign Unified SecOps Platform Directory Traversal Information Disclosure Vulnerability — Unified SecOps Platform 6.5AIMediumAI2024-08-06
CVE-2024-7551 juzaweb CMS Theme Editor default path traversal — CMS 2.7 Low2024-08-06
CVE-2024-5709 WPBakery <= 7.7 - Authenticated (Author+) Local File Inclusion — WPBakery Page Builder 8.8 High2024-08-06
CVE-2024-6781 Calibre Arbitrary File Read — Calibre 7.5 High2024-08-06
CVE-2024-23657 Path Traversal: '../filedir' in Nuxt Devtools — nuxt 8.8 High2024-08-05
CVE-2024-38878 Siemens Omnivise T3000 路径遍历漏洞 — Omnivise T3000 Application Server R9.2 7.2 High2024-08-02
CVE-2024-38746 WordPress MakeStories (for Google Web Stories) plugin <= 3.0.3 - Arbitrary File Download and SSRF vulnerability — MakeStories (for Google Web Stories) 7.1 High2024-08-01
CVE-2024-38768 WordPress The Pack Elementor addons plugin <= 2.0.8.6 - Local File Inclusion vulnerability — The Pack Elementor addons 4.3 Medium2024-08-01
CVE-2024-38772 WordPress JetWidgets for Elementor and WooCommerce plugin <= 1.1.7 - Contributor+ Limited Local File Inclusion vulnerability — JetWidgets for Elementor and WooCommerce 6.5 Medium2024-08-01
CVE-2024-39619 WordPress ListingPro plugin <= 2.9.4 - Unauthenticated Local File Inclusion vulnerability — ListingPro 9.0 Critical2024-08-01
CVE-2024-39621 WordPress ListingPro plugin <= 2.9.4 - Local File Inclusion vulnerability — ListingPro 8.0 High2024-08-01
CVE-2024-39624 WordPress ListingPro theme <= 2.9.4 - Local File Inclusion vulnerability — ListingPro 8.5 High2024-08-01
CVE-2024-7340 W&B Weave server remote arbitrary file leak and privilege escalation 8.8 High2024-07-31
CVE-2024-37129 Dell Inventory Collector 安全漏洞 — Dell Inventory Collector 6.7 Medium2024-07-31
CVE-2024-6255 Path Traversal in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 8.2 High2024-07-31
CVE-2024-41695 Cybonet - CWE-22: Improper Limitation of a Pathname to a Restricted Directory — PineApp Mail Relay 7.5 High2024-07-30
CVE-2024-7248 Comodo Internet Security Pro Directory Traversal Local Privilege Escalation Vulnerability — Internet Security Pro 7.8AIHighAI2024-07-29
CVE-2024-41799 tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users — tgstation-server 8.4 High2024-07-29
CVE-2024-6885 MaxiBlocks: 2200+ Patterns, 190 Pages, 14.2K Icons & 100 Styles <= 1.9.2 - Authenticated (Subscriber+) Arbitrary File Deletion — MaxiBlocks Builder | 17,000+ Design Assets, Patterns, Icons & Starter Sites 8.1 High2024-07-23
CVE-2024-6791 Directory Path Traversal Vulnerability in NI VeriStand with vsmodel Files — VeriStand 7.8 High2024-07-22
CVE-2024-39688 fishaudio/Bert-VITS2 Limited File Write in webui_preprocess.py generate_config function — Bert-VITS2 6.5 Medium2024-07-22
CVE-2024-6949 Gargaj wuhu path traversal — wuhu 4.3 Medium2024-07-21

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.