Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-1593 Path Traversal via Parameter Smuggling in mlflow/mlflow — mlflow/mlflow 9.1 -2024-04-16
CVE-2023-38511 iTop Dashboard editor vulnerable dashboard config file parameter — iTop 5.0 Medium2024-04-15
CVE-2024-3783 Path Traversal vulnerability in WBSAirback — White Bear Solutions 7.7 High2024-04-15
CVE-2023-52144 WordPress Product Feed Manager plugin <= 7.3.15 - Directory Traversal vulnerability — Product Feed Manager 5.5 Medium2024-04-15
CVE-2024-3737 cym1102 nginxWebUI addOver findCountByQuery path traversal — nginxWebUI 6.3 Medium2024-04-13
CVE-2024-31462 Limited file write in Stable-diffusion-webui - GHSL-2024-010 — stable-diffusion-webui 6.3 Medium2024-04-12
CVE-2024-1511 Path Traversal Vulnerability in parisneo/lollms-webui — parisneo/lollms-webui 8.8AIHighAI2024-04-10
CVE-2024-1728 Local File Inclusion in gradio-app/gradio — gradio-app/gradio 9.8AICriticalAI2024-04-10
CVE-2024-31287 WordPress Media Library Folders plugin <= 8.1.8 - Directory Traversal vulnerability — Media Library Folders 6.5 Medium2024-04-10
CVE-2024-31240 WordPress WP Poll Maker plugin <= 3.1 - Auth. Arbitrary File Deletion vulnerability — WP Poll Maker 7.7 High2024-04-10
CVE-2024-1790 Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read — Ajax Load More – Infinite Scroll, Load More, & Lazy Load 4.9 Medium2024-04-09
CVE-2024-1974 HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal — HT Mega Addons for Elementor – Elementor Widgets & Template Builder 8.8 High2024-04-09
CVE-2024-31457 gin-vue-admin background arbitrary code coverage vulnerability — gin-vue-admin 7.7 High2024-04-09
CVE-2024-31487 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox 5.8 Medium2024-04-09
CVE-2023-47541 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox 6.5 Medium2024-04-09
CVE-2024-23671 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox 7.9 High2024-04-09
CVE-2024-2224 Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466) — GravityZone Control Center (On Premises) 8.1 High2024-04-09
CVE-2024-31860 Apache Zeppelin: Path traversal vulnerability — Apache Zeppelin 6.5AIMediumAI2024-04-09
CVE-2024-31978 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 7.6 High2024-04-09
CVE-2023-52544 Huawei HarmonyOS 安全漏洞 — HarmonyOS 7.5AIHighAI2024-04-08
CVE-2024-30417 Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.5AIMediumAI2024-04-07
CVE-2024-0406 Mholt/archiver: path traversal vulnerability 6.1 Medium2024-04-06
CVE-2024-22328 IBM Maximo Application Suite information disclosure — Maximo Application Suite 7.5 High2024-04-06
CVE-2024-31851 CData Sync 安全漏洞 — Sync 8.6 High2024-04-05
CVE-2024-31850 CData Arc 安全漏洞 — Arc 8.6 High2024-04-05
CVE-2024-31849 CData Connect 安全漏洞 — Connect 9.8 Critical2024-04-05
CVE-2024-31848 CData API Server 安全漏洞 — API Server 9.8 Critical2024-04-05
CVE-2024-31220 Sunshine vulnerable to remote unauthenticated arbitrary file read — Sunshine 7.3 High2024-04-05
CVE-2024-3311 Dreamer CMS ThemesController.java ZipUtils.unZipFiles path traversal — CMS 6.3 Medium2024-04-04
CVE-2024-30270 mailcow Path Traversal and Arbitrary Code Execution Vulnerability — mailcow-dockerized 6.2 Medium2024-04-04

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.