Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3327

3327 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-27101 Dell Secure Connect Gateway 路径遍历漏洞 — Secure Connect Gateway 4.7 Medium2026-04-01
CVE-2026-5258 Sanster IOPaint File Manager file_manager.py _get_file path traversal — IOPaint 7.3 High2026-04-01
CVE-2026-34451 Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories — anthropic-sdk-typescript 8.1 -2026-03-31
CVE-2026-5203 CMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversal — CMS Made Simple 4.7 Medium2026-03-31
CVE-2026-33581 OpenClaw < 2026.3.24 - Arbitrary File Read via mediaUrl and fileUrl Parameters — OpenClaw 6.5 Medium2026-03-31
CVE-2025-10559 Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — DELMIA Factory Resource Manager 7.1 High2026-03-31
CVE-2026-34070 LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions — langchain 7.5 High2026-03-31
CVE-2026-32727 SciTokens: Authorization Bypass via Path Traversal in Scope Validation — scitokens 8.1 High2026-03-31
CVE-2026-30940 baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE — basercms 7.2 High2026-03-31
CVE-2026-27018 Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme — gotenberg 5.3 -2026-03-30
CVE-2026-33027 Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory — nginx-ui 7.1 -2026-03-30
CVE-2026-5014 elecV2 elecV2P Wildcard log path.join path traversal — elecV2P 5.3 Medium2026-03-28
CVE-2026-5013 elecV2 elecV2P :key path.join path traversal — elecV2P 5.3 Medium2026-03-28
CVE-2026-4999 z-9527 admin isImg Check upload.js uploadFile path traversal — admin 6.3 Medium2026-03-28
CVE-2026-4997 Sinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversal — PandasAI 5.3 Medium2026-03-28
CVE-2016-20048 iSelect 1.4.0-2+b1 Local Buffer Overflow via key parameter — iSelect 8.4 High2026-03-28
CVE-2016-20041 Yasr 0.6.9-5 Buffer Overflow via Command-line Parameter — Yasr Screen Reader 8.4 High2026-03-28
CVE-2016-20040 TiEmu 3.03-nogdb+dfsg-3 Buffer Overflow via ROM Parameter — Texas Instrument Emulator 8.4 High2026-03-28
CVE-2026-33989 @mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools — mobile-mcp 8.1 High2026-03-27
CVE-2026-5027 Langflow - Path Traversal Arbitrary File Write via upload_user_file — langflow 8.8 High2026-03-27
CVE-2026-33748 BuildKit Git URL subdir component can cause access to restricted files — buildkit 7.5 -2026-03-27
CVE-2026-4619 NEC Platforms Aterm Series 安全漏洞 — Aterm WX3600HP 7.5 -2026-03-27
CVE-2026-0394 Open-Xchange OX Dovecot Pro 安全漏洞 — OX Dovecot Pro 5.3 Medium2026-03-27
CVE-2026-33747 BuildKit vulnerable to malicious frontend causing file escape outside of storage root — buildkit 8.4 High2026-03-27
CVE-2026-28786 Open WebUI vulnerable to Path Traversal in `POST /api/v1/audio/transcriptions` — open-webui 4.3 Medium2026-03-26
CVE-2026-33945 Abitrary file write through systemd-creds option — incus 10.0 Critical2026-03-26
CVE-2026-33686 Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtil — sharp 8.8 High2026-03-26
CVE-2026-33670 SiYuan has directory traversal within its publishing service — siyuan 9.8 Critical2026-03-26
CVE-2026-33645 Fireshare has Path Traversal Arbitrary File Write in `/api/uploadChunked` — fireshare 7.1 High2026-03-26
CVE-2026-0964 Libssh: improper sanitation of paths received from scp servers — Red Hat Enterprise Linux 10 8.8 -2026-03-26

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3327 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.