Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-4098 Shariff Wrapper <= 4.6.13 - Unauthenticated Local File Inclusion — Shariff Wrapper 9.8 Critical2024-06-20
CVE-2024-5182 Path Traversal in mudler/localai — mudler/localai 7.5 -2024-06-19
CVE-2024-38358 Symlink bypasses filesystem sandbox in wasmer — wasmer 2.9 Low2024-06-19
CVE-2024-36117 Path traversal while serving Reposilite javadoc expanded files — reposilite 8.6 High2024-06-19
CVE-2024-36116 Path traversal in Reposilite javadoc file expansion — reposilite 7.5 High2024-06-19
CVE-2024-37902 Path thraversal in DeepJavaLibrary — djl 10.0 Critical2024-06-17
CVE-2024-6044 D-Link router - Arbitrary File Reading — G403 6.5 Medium2024-06-17
CVE-2024-2024 Folders Pro <= 3.0.2 - Authenticated(Author+) Arbitrary File Upload via handle_folders_file_upload — Folders Pro 8.8 High2024-06-14
CVE-2024-2023 Folders <= 3.0 and Folders Pro <= 3.0.2 - Directory Traversal via handle_folders_file_upload — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager 4.3 Medium2024-06-14
CVE-2024-27178 Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 7.2 High2024-06-14
CVE-2024-27177 Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 7.2 High2024-06-14
CVE-2024-27176 Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 7.2 High2024-06-14
CVE-2024-27174 insecure upload — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-27173 insecure upload — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-27145 Multiple Post-authenticated Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-27144 Pre-authenticated Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-34129 Acrobat Android : OverSecured Finding : Overwriting arbitrary files via attacker-controlled output file paths — Acrobat Mobile Sign Android 7.5 High2024-06-13
CVE-2024-37037 Schneider Electric SAGE RTUs 路径遍历漏洞 — Sage 1410 8.1 High2024-06-12
CVE-2024-5154 Cri-o: malicious container can create symlink on host 8.1 High2024-06-12
CVE-2024-4315 LFI Vulnerability due to Lack of Path Sanitization in parisneo/lollms — parisneo/lollms 9.8AICriticalAI2024-06-12
CVE-2024-37169 @jmondi/url-to-png arbitrary file read via Playwright's screenshot feature exploiting file wrapper — url-to-png 5.3 Medium2024-06-10
CVE-2024-36418 SuiteCRM authenticated RCE using connectors — SuiteCRM 8.6 High2024-06-10
CVE-2024-35754 WordPress Ovic Importer plugin <= 1.6.3 - Arbitrary File Download vulnerability — Ovic Importer 7.5 High2024-06-10
CVE-2024-35745 WordPress Strategery Migrations plugin <= 1.0 - Arbitrary File Deletion vulnerability — Strategery Migrations 7.5 High2024-06-10
CVE-2024-35744 WordPress Upunzipper plugin <= 1.0.0 - Arbitrary File Deletion vulnerability — Upunzipper 8.6 High2024-06-10
CVE-2024-35743 WordPress SC filechecker plugin <= 0.6 - Arbitrary File Deletion vulnerability — SC filechecker 8.6 High2024-06-10
CVE-2024-35712 WordPress Database Cleaner: Clean, Optimize & Repair plugin <= 1.0.5 - Arbitrary File Read vulnerability — Database Cleaner 4.9 Medium2024-06-10
CVE-2024-35677 WordPress MegaMenu plugin <= 2.3.12 - Unauthenticated Local File Inclusion vulnerability — MegaMenu 9.0 Critical2024-06-10
CVE-2024-35658 WordPress Checkout Field Editor for WooCommerce (Pro) plugin <= 3.6.2 - Unauthenticated Arbitrary File Deletion vulnerability — Checkout Field Editor for WooCommerce (Pro) 8.6 High2024-06-10
CVE-2024-34762 Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability — Advanced Custom Fields PRO 9.9 Critical2024-06-10

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.