Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-32137 D-Link DAP-1360 webproc WEB_DisplayPage Directory Traversal Information Disclosure Vulnerability — DAP-1360 6.5 -2024-05-03
CVE-2023-27326 Parallels Desktop Toolgate Directory Traversal Local Privilege Escalation Vulnerability — Desktop 8.2 -2024-05-03
CVE-2024-34033 Path Traversal vulnerability in Delta Electronics DIAEnergie — DIAEnergie 8.8 High2024-05-03
CVE-2024-3107 Spectra – WordPress Gutenberg Blocks <= 2.12.6 - Authenticated (Contributor+) Path Traversal — Spectra Gutenberg Blocks – Website Builder for the Block Editor 4.3 Medium2024-05-02
CVE-2024-3195 MailCleaner Admin Endpoints path traversal — MailCleaner 4.7 Medium2024-04-29
CVE-2024-4297 HGiga iSherlock - Arbitrary File Download — iSherlock 4.5 4.9 Medium2024-04-29
CVE-2024-4296 HGiga iSherlock - Arbitrary File Download — iSherlock 4.5 4.9 Medium2024-04-29
CVE-2024-3034 BackUpWordPress <= 3.13 - Authenticated (Admin+) Directory Traversal — BackUpWordPress 2.7 Low2024-04-27
CVE-2023-41290 QuFirewall — QuFirewall 4.1 Medium2024-04-26
CVE-2023-41291 QuFirewall — QuFirewall 5.5 Medium2024-04-26
CVE-2023-51364 QTS, QuTS hero, QuTScloud — QTS 8.7 High2024-04-26
CVE-2023-51365 QTS, QuTS hero, QuTScloud — QTS 8.7 High2024-04-26
CVE-2024-2434 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab — GitLab 8.5 High2024-04-25
CVE-2022-45852 WordPress WP-FormAssembly plugin <= 2.0.5 - Auth. Arbitrary File Read vulnerability — WP-FormAssembly 6.5 Medium2024-04-24
CVE-2024-32869 Hono vulnerable to Restricted Directory Traversal in serveStatic with deno — hono 5.3 Medium2024-04-23
CVE-2024-31450 Owncast vulnerable to arbitrary file deletion in emoji.go (GHSL-2023-277) — owncast 2.7 Low2024-04-19
CVE-2023-50885 WordPress Store Locator WordPress Plugin <= 1.4.14 is vulnerable to Arbitrary File Deletion — Store Locator WordPress 6.8 Medium2024-04-18
CVE-2023-47843 WordPress CataBlog Plugin <= 1.7.0 is vulnerable to Arbitrary File Deletion — CataBlog 7.6 High2024-04-18
CVE-2023-3675 Insufficient input validation when downloading certain file types. — GateManager 6.5 Medium2024-04-18
CVE-2024-28073 SolarWinds Serv-U Directory Traversal Remote Code Execution Vulnerability — ServU 8.4 High2024-04-17
CVE-2024-1132 Keycloak: path transversal in redirection validation 8.1 High2024-04-17
CVE-2024-32024 Kohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`) — kohya_ss 6.5 Medium2024-04-16
CVE-2024-32023 Kohya_ss vulnerable to path injection in `common_gui.py` `find_and_replace` function (`GHSL-2024-024`) — kohya_ss 6.5 Medium2024-04-16
CVE-2024-31451 Limited file write in routes.py (GHSL-2023-250) — DocsGPT 5.3 Medium2024-04-16
CVE-2024-1961 Path Traversal leading to Arbitrary File Write and RCE in vertaai/modeldb — vertaai/modeldb 9.8 -2024-04-16
CVE-2024-1558 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 6.5 -2024-04-16
CVE-2024-1594 Local File Read via Path Traversal in mlflow/mlflow — mlflow/mlflow 7.5 -2024-04-16
CVE-2024-3571 Path Traversal in langchain-ai/langchain — langchain-ai/langchain 9.8 -2024-04-16
CVE-2024-1483 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 7.5 -2024-04-16
CVE-2024-1560 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 7.5 -2024-04-16

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.