Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0818 PaddlePaddle 路径遍历漏洞 — paddlepaddle/paddle 9.1AICriticalAI2024-03-07
CVE-2024-1142 Sonatype IQ Server - Path Traversal — IQ Server 5.4 Medium2024-03-06
CVE-2023-38366 IBM FileNet Content Manager directory traversal — Filenet Content Manager 5.3 Medium2024-03-01
CVE-2024-2045 Session 1.17.5 - LFR via chat attachment — Session 5.5 Medium2024-02-29
CVE-2024-23946 Apache OFBiz: Path traversal or file inclusion — Apache OFBiz 9.1 -2024-02-28
CVE-2024-25065 Apache OFBiz: Path traversal allowing authentication bypass. — Apache OFBiz 9.1 -2024-02-28
CVE-2024-0763 Improper validation of document removal parameter — mintplex-labs/anything-llm 8.1 -2024-02-27
CVE-2024-27081 ESPHome remote code execution via arbitrary file write — esphome 7.2 High2024-02-26
CVE-2024-1165 Brizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory Traversal — Brizy – Page Builder 4.3 Medium2024-02-24
CVE-2024-27318 Open Neural Network Exchange 安全漏洞 — onnx 7.5 High2024-02-23
CVE-2024-26150 `@backstage/backend-common` vulnerable to path traversal through symlinks — backstage 8.7 High2024-02-23
CVE-2023-24416 WordPress All In One Favicon Plugin <= 4.7 is vulnerable to Arbitrary File Deletion — All In One Favicon 6.8 Medium2024-02-23
CVE-2024-1704 ZhongBangKeJi CRMEB crud delete path traversal — CRMEB 5.5 Medium2024-02-21
CVE-2024-1708 Improper limitation of a pathname to a restricted directory (“path traversal”) — ScreenConnect 8.4 High2024-02-21
CVE-2024-26129 Prestashop vulnerable to path disclosure in JavaScript variable — PrestaShop 5.8 Medium2024-02-19
CVE-2024-25123 Path Manipulation in file mslib/index.py in MSS — MSS 7.3 High2024-02-15
CVE-2024-23477 SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability — Access Rights Manager 7.9 High2024-02-15
CVE-2024-23476 SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability — Access Rights Manager 9.6 Critical2024-02-15
CVE-2024-23479 SolarWinds Access Rights Manager (ARM) Directory Traversal Remote Code Execution Vulnerability — Access Rights Manager 9.6 Critical2024-02-15
CVE-2024-26261 Hgiga OAKlouds - Arbitrary File Read And Delete — OAKlouds 9.8 Critical2024-02-15
CVE-2024-25620 Dependency management path traversal in helm — helm 6.4 Medium2024-02-14
CVE-2024-23607 F5OS QKView utility vulnerability — F5OS - Appliance 5.5 Medium2024-02-14
CVE-2023-5123 Improper Path Sanitization in JSON Datasource Plugin — grafana-json-datasource 8.0 High2024-02-14
CVE-2024-25125 Absolute path traversal vulnerability in digdag server — digdag 5.3 Medium2024-02-14
CVE-2024-1485 Registry-support: decompress can delete files outside scope via relative paths 8.0 High2024-02-13
CVE-2024-1082 Path traversal vulnerability in GitHub Enterprise Server that allowed arbitrary file read with a specially crafted GitHub Pages artifact upload — Enterprise Server 6.3 Medium2024-02-13
CVE-2024-1163 Path traversal vulnerability in mapshaper — mbloch/mapshaper 9.8 -2024-02-13
CVE-2024-23833 OpenRefine JDBC Attack Vulnerability — OpenRefine 7.5 High2024-02-12
CVE-2024-1433 KDE Plasma Workspace Theme File eventpluginsmanager.cpp enabledPlugins path traversal — Plasma Workspace 3.1 Low2024-02-11
CVE-2024-0849 Leanote 2.7.0 - Local File Read — Leanote 5.0 Medium2024-02-07

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.