Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-6032 Schneider Electric Galaxy VS和Schneider Electric Galaxy VL 安全漏洞 — Galaxy VS 5.3 Medium2023-11-15
CVE-2023-40055 SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-09
CVE-2023-40054 SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-09
CVE-2023-46253 Remote code execution in Squidex — squidex 9.1 Critical2023-11-07
CVE-2023-39299 Music Station — Music Station 7.5 High2023-11-03
CVE-2023-3961 Samba: smbd allows client access to unix domain sockets on the file system as root — Red Hat Enterprise Linux 8 9.1 Critical2023-11-03
CVE-2023-41356 WisdomGarden Tronclass ilearn - Path Traversal — Tronclass ilearn 6.5 Medium2023-11-03
CVE-2023-41344 NCSIST ManageEngine MDM - Path Traversal — MDM 7.5 High2023-11-03
CVE-2023-20220 Cisco Firepower Management Center 安全漏洞 — Cisco Firepower Management Center 7.2 High2023-11-01
CVE-2023-33227 Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-01
CVE-2023-33226 Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-01
CVE-2023-2621 Hitachi Energy MACH System Software 路径遍历漏洞 — MACH System Software 6.5 Medium2023-11-01
CVE-2023-46237 FOG path traversal via unauthenticated endpoint — fogproject 5.8 Medium2023-10-31
CVE-2023-43648 baserCMS Directory Traversal vulnerability in Form submission data management Feature — basercms 4.9 Medium2023-10-30
CVE-2023-42804 BigBlueButton Path Traversal – Reading Certain File Extensions — bigbluebutton 3.1 Low2023-10-30
CVE-2005-10002 almosteffortless secure-files Plugin secure-files.php sf_downloads path traversal — secure-files Plugin 5.5 Medium2023-10-29
CVE-2023-30967 Gotham Orbital Simulator path traversal — com.palantir.meta:orbital-simulator 9.8 Critical2023-10-25
CVE-2023-42488 EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — v3.0.6433.1964 7.5 High2023-10-25
CVE-2023-26578 Arbitrary File Upload to Web Root In IDAttend’s IDWeb Application — IDWeb 8.8 High2023-10-25
CVE-2023-46122 Arbitrary file write via archive extraction (Zip Slip) vulnerability in sbt — sbt 3.9 Low2023-10-23
CVE-2023-44256 Fortinet FortiAnalyzer 代码问题漏洞 — FortiAnalyzer 6.4 Medium2023-10-20
CVE-2023-5414 Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress 9.1 Critical2023-10-20
CVE-2023-45823 Arbitrary file read in Artifact Hub — hub 7.5 High2023-10-19
CVE-2023-35187 SolarWinds Access Rights Manager Directory Traversal Remote Code Execution Vulnerability — Access Rights Manager 8.8 High2023-10-19
CVE-2023-35185 SolarWinds Access Rights Manager OpenFile Directory Traversal Remote Code Execution Vulnerability — Access Rights Manager 6.8 Medium2023-10-19
CVE-2023-5212 AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 9.6 Critical2023-10-19
CVE-2023-5241 AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services 9.6 Critical2023-10-19
CVE-2023-43801 Path traversal in Arduino Create Agent — arduino-create-agent 6.1 Medium2023-10-18
CVE-2023-43802 Path traversal in Arduino Create Agent — arduino-create-agent 7.1 High2023-10-18
CVE-2023-43803 Path traversal in Arduino Create Agent — arduino-create-agent 6.1 Medium2023-10-18

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.