Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-24591 Allegro 路径遍历漏洞 — ClearML 8.0 High2024-02-06
CVE-2024-23673 Apache Sling Servlets Resolver: Malicious code execution via path traversal — Apache Sling Servlets Resolver 8.5 High2024-02-06
CVE-2024-0964 LFI in Gradio — gradio-app/gradio 9.8 -2024-02-05
CVE-2024-0380 WP Recipe Maker <= 9.1.0 - Directory Traversal — WP Recipe Maker 5.4 Medium2024-02-05
CVE-2024-0221 Photo Gallery by 10Web - Mobile-Friendly Image Gallery <= 1.8.19 - Directory Traversal to Arbitrary File Rename — Photo Gallery by 10Web – Mobile-Friendly Image Gallery 9.1 Critical2024-02-05
CVE-2023-7077 Sharp NEC Displays 路径遍历漏洞 — P403, P463, P553, P703, P801, X554UN, X464UN, X554UNS, X464UNV, X474HB, X464UNS, X554UNV, X555UNS, X555UNV, X754HB, X554HB, E705, E805, E905, UN551S, UN551VS, X551UHD, X651UHD, X841UHD, X981UHD, MD551C8 9.8 -2024-02-05
CVE-2023-45027 QTS, QuTS hero, QuTScloud — QTS 5.5 Medium2024-02-02
CVE-2023-45026 QTS, QuTS hero, QuTScloud — QTS 5.5 Medium2024-02-02
CVE-2023-38019 IBM SOAR QRadar Plugin App directory traversal — SOAR QRadar Plugin App 8.1 High2024-02-02
CVE-2024-21852 Rapid SCADA Path Traversal — Rapid SCADA 8.8 High2024-02-01
CVE-2024-24756 Crafatar path traversal vulnerability — crafatar 7.5 High2024-02-01
CVE-2024-24569 `ZipSecurity#isBelowCurrentDirectory` is vulnerable to partial-path traversal vulnerability — java-security-toolkit 5.4 Medium2024-02-01
CVE-2024-23652 BuildKit possible host system access from mount stub cleaner — buildkit 10.0 Critical2024-01-31
CVE-2024-24579 Tar path traversal in stereoscope when processing OCI tar archives — stereoscope 5.3 Medium2024-01-31
CVE-2024-24565 CrateDB database has an arbitrary file read vulnerability — crate 5.7 Medium2024-01-30
CVE-2024-23334 aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal — aiohttp 5.9 Medium2024-01-29
CVE-2024-23827 Nginx-UI arbitrary file write through the Import Certificate feature — nginx-ui 9.8 Critical2024-01-29
CVE-2024-23822 Thruk Incorrect limitation of a pathname to a restricted directory (Path Traversal) (CWE-22) — Thruk 5.4 Medium2024-01-29
CVE-2024-0697 Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal — Backuply – Backup, Restore, Migrate and Clone 6.5 Medium2024-01-27
CVE-2024-0402 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab — GitLab 9.9 Critical2024-01-26
CVE-2024-22204 Whoogle Search Limited File Write vulnerability — whoogle-search 5.3 Medium2024-01-23
CVE-2024-23340 @hono/node-server can't handle "double dots" in URL — node-server 5.3 Medium2024-01-22
CVE-2022-45792 Directory Traversal in Project File Format allows overwrite (Zip Slip) — Sysmac Studio 7.8 High2024-01-22
CVE-2023-44395 Autolab has Path Traversal vulnerability in Assessment functionality — Autolab 4.9 Medium2024-01-22
CVE-2024-0769 D-Link DIR-859 HTTP POST Request hedwig.cgi path traversal — DIR-859 5.3 Medium2024-01-21
CVE-2023-35020 IBM Sterling Control Center directory traversal — Sterling Control Center 5.4 Medium2024-01-19
CVE-2023-5097 HYPR 输入验证错误漏洞 — Workforce Access 7.0 High2024-01-16
CVE-2023-46749 Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used together with path rewriting — Apache Shiro 9.8 -2024-01-15
CVE-2023-48383 NetVision Information airPASS - Path Traversal — airPASS 7.5 High2024-01-15
CVE-2023-49801 Lif Auth Server vulnerable to uncontrolled data in path expression — Lif-Auth-Server 4.2 Medium2024-01-12

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.