Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-34216 Second Order Command-injection Vulnerability in the Key-delete Function — TN-5900 Series 8.1 High2023-08-17
CVE-2023-20229 Cisco Duo 路径遍历漏洞 — Cisco Duo Device Health Application 7.1 High2023-08-16
CVE-2023-40028 Arbitrary file read via symlinks in Ghost — Ghost 4.9 Medium2023-08-15
CVE-2023-39402 Huawei HarmonyOS 路径遍历漏洞 — HarmonyOS 9.8 -2023-08-13
CVE-2023-39401 Huawei HarmonyOS 安全漏洞 — HarmonyOS 9.8 -2023-08-13
CVE-2023-39400 Huawei HarmonyOS 路径遍历漏洞 — HarmonyOS 9.8 -2023-08-13
CVE-2023-39964 1Panel O&M management panel has a background arbitrary file reading vulnerability — 1Panel 7.5 High2023-08-10
CVE-2023-39957 Path traversal allows tricking the Talk Android app into writing files into it's root directory — security-advisories 3.3 -2023-08-10
CVE-2023-36534 Zoom Client 路径遍历漏洞 — Zoom Desktop Client for Windows 9.3 Critical2023-08-08
CVE-2023-38176 Azure Arc-Enabled Servers Elevation of Privilege Vulnerability — Azure Arc-Enabled Servers 7.0 High2023-08-08
CVE-2023-39528 PrestaShop vulnerable to file reading through path traversal — PrestaShop 6.8 Medium2023-08-07
CVE-2023-39525 PrestaShop vulnerable to path traversal — PrestaShop 6.5 Medium2023-08-07
CVE-2020-26065 Cisco SD-WAN vManage Software 路径遍历漏洞 — Cisco SD-WAN vManage 6.5 -2023-08-04
CVE-2023-38702 Knowage Server vulnerable to path traversal via upload functionality — Knowage-Server 10.0 Critical2023-08-04
CVE-2023-38695 cypress-image-snapshot vulnerable to insecure snapshot file names — cypress-image-snapshot 6.5 Medium2023-08-04
CVE-2023-37896 Nuclei Path Traversal vulnerability — nuclei 7.5 High2023-08-04
CVE-2023-38708 Pimcore Path Traversal Vulnerability in AssetController:importServerFilesAction — pimcore 6.3 Medium2023-08-04
CVE-2023-3348 Directory traversal vulnerability in Cloudflare Wrangler — Wrangler 5.7 Medium2023-08-03
CVE-2023-3385 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab — GitLab 6.3 Medium2023-08-01
CVE-2023-31427 Knowledge of full path name — Fabric OS 7.8 High2023-08-01
CVE-2023-35016 IBM Security Verify Governance path traversal — Security Verify Governance, Identity Manager 6.5 Medium2023-07-31
CVE-2023-37218 Tadiran Telecom Aeonix - CWE-22: Improper Limitation of a Pathname to a Restricted Directory — Telecom Aeonix 7.5 High2023-07-30
CVE-2023-23842 SolarWinds Network Configuration Manager Directory Traversal Vulnerability — Network Configuration Manager 7.2 High2023-07-26
CVE-2023-37460 Plexus Archiver vulnerable to Arbitrary File Creation in AbstractUnArchiver — plexus-archiver 8.1 High2023-07-25
CVE-2023-26045 NodeBB vulnerable to path traversal and code execution via prototype vulnerability — NodeBB 10.0 Critical2023-07-24
CVE-2023-34478 Apache Shiro before 1.12.0, or 2.0.0-alpha-3, may be susceptible to a path traversal attack when used together with APIs or other web frameworks that route requests based on non-normalized requests. — Apache Shiro 9.8 -2023-07-24
CVE-2023-3813 Jupiter X Core <= 4.6.6 - Unauthenticated Arbitrary File Download — Jupiter X Core 7.5 High2023-07-21
CVE-2023-37476 Zip slip in OpenRefine — OpenRefine 5.5 Medium2023-07-17
CVE-2023-37461 Path traversal in metersphere — metersphere 5.6 Medium2023-07-17
CVE-2023-37474 Path traversal in copyparty — copyparty 9.8 -2023-07-14

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.