Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-32703 WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary File Deletion vulnerability — ARForms 7.7 High2024-06-09
CVE-2024-32778 WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability — Contest Gallery 8.5 High2024-06-09
CVE-2024-5187 Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx — onnx/onnx 8.8AIHighAI2024-06-06
CVE-2024-3322 Path Traversal in parisneo/lollms-webui — parisneo/lollms-webui 9.3AICriticalAI2024-06-06
CVE-2024-1873 Path Traversal and Denial of Service in parisneo/lollms-webui — parisneo/lollms-webui 7.5AIHighAI2024-06-06
CVE-2024-3234 Path Traversal in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 7.5AIHighAI2024-06-06
CVE-2024-0520 Remote Code Execution due to Full Controlled File Write in mlflow/mlflow — mlflow/mlflow 9.8AICriticalAI2024-06-06
CVE-2024-5550 Exposure of Sensitive Information via Arbitrary System Path Lookup in h2oai/h2o-3 — h2oai/h2o-3 4.3AIMediumAI2024-06-06
CVE-2024-23793 Upload of files outside application directory — OTRS 6.3 Medium2024-06-06
CVE-2024-4941 Local File Inclusion in JSON component in gradio-app/gradio — gradio-app/gradio 7.5AIHighAI2024-06-06
CVE-2024-5505 NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability — ProSAFE Network Management System 8.8AIHighAI2024-06-06
CVE-2024-28995 SolarWinds Serv-U L Directory Transversal Vulnerability — SolarWinds Serv-U 8.6 High2024-06-06
CVE-2024-5153 Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion — Startklar Elementor Addons 9.1 Critical2024-06-06
CVE-2024-5179 Cowidgets – Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion — Cowidgets – Elementor Addons 8.8 High2024-06-06
CVE-2024-35634 Woocommerce – Recent Purchases plugin <= 1.0.1 - File Inclusion vulnerability — Woocommerce – Recent Purchases 4.9 Medium2024-06-04
CVE-2024-34554 WordPress Stockholm Core plugin <= 2.4.1 - Local File Inclusion vulnerability — Stockholm Core 8.5 High2024-06-04
CVE-2024-34552 WordPress Stockholm theme <= 9.6 - Local File Inclusion vulnerability — Stockholm 8.5 High2024-06-04
CVE-2024-34551 WordPress Stockholm theme <= 9.6 - Unauthenticated Local File Inclusion vulnerability — Stockholm 9.0 Critical2024-06-04
CVE-2024-34384 WordPress Sina Extension for Elementor plugin <= 3.5.1 - Local File Inclusion vulnerability — Sina Extension for Elementor 6.5 Medium2024-06-04
CVE-2024-33628 WordPress XforWooCommerce plugin <= 2.0.2 - Authenticated Local File Inclusion vulnerability — XforWooCommerce 8.8 High2024-06-04
CVE-2024-33568 WordPress Element Pack Pro plugin < 7.19.3 - Arbitrary File Read and Phar Deserialization vulnerability — Element Pack Pro 8.5 High2024-06-04
CVE-2024-33560 WordPress XStore theme <= 9.3.8 - Unauthenticated Local File Inclusion vulnerability — XStore 9.0 Critical2024-06-04
CVE-2024-33557 WordPress XStore Core plugin <= 5.3.8 - Local File Inclusion vulnerability — XStore Core 8.5 High2024-06-04
CVE-2024-33541 WordPress Better Elementor Addons plugin <= 1.4.1 - Local File Inclusion vulnerability — Better Elementor Addons 6.5 Medium2024-06-04
CVE-2024-36104 Apache OFBiz: Path traversal leading to a RCE — Apache OFBiz 7.5AIHighAI2024-06-04
CVE-2024-27776 MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — DeviceHub 9.8 Critical2024-06-02
CVE-2024-5433 Path Traversal in Campbell Scientific CSI Web Server and RTMC — CSI Web Server and RTMC 7.5AIHighAI2024-05-28
CVE-2024-35219 OpenAPI Generator Online - Arbitrary File Read/Delete — openapi-generator 8.3 High2024-05-27
CVE-2024-5353 anji-plus AJ-Report ZIP File decompress path traversal — AJ-Report 6.3 Medium2024-05-26
CVE-2024-34060 Arbitrary File Write in IRIS EVTX Pipeline — iris-evtx-module 8.8 High2024-05-23

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.