Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2020-36728 Adning Advertising <= 1.5.5 - Unauthenticated Arbitrary File Deletion via Path Traversal — Adning Advertising 6.5 Medium2023-06-07
CVE-2023-3031 Prestahop module King-Avis - Path traversal — King-Avis 4.9 Medium2023-06-02
CVE-2023-2909 A Directory traversal vulnerability was found on EZ Sync service of ADM — ADM 8.5 High2023-05-31
CVE-2023-2435 Blog-in-Blog <= 2.0.0 - Authenticated (Editor+) Local File Inclusion via Shortcode — Blog-in-Blog 7.2 High2023-05-31
CVE-2023-33177 Xibo CMS vulnerable to Remote Code Execution through Zip Slip — xibo-cms 8.8 High2023-05-30
CVE-2023-32676 Autolab tar slip in Install Assessment functionality (`GHSL-2023-081`) — Autolab 6.7 Medium2023-05-26
CVE-2023-32317 Autolab tar slip in cheat checker functionality (`GHSL-2023-082`) — Autolab 6.7 Medium2023-05-26
CVE-2023-32315 Openfire administration console authentication bypass — Openfire 8.6 High2023-05-26
CVE-2022-36328 Path Traversal Vulnerability leading to an arbitrary file read in Western Digital devices — My Cloud Home and My Cloud Home Duo 5.8 Medium2023-05-18
CVE-2022-36327 Path traversal vulnerability leading to an arbitrary file write in Western Digital devices — My Cloud Home and My Cloud Home Duo 5.8 Medium2023-05-18
CVE-2023-32322 Arbitrary file read in Ombi — Ombi 4.9 Medium2023-05-18
CVE-2023-2745 WordPress Core < 6.2.1 - Directory Traversal — WordPress 5.4 Medium2023-05-17
CVE-2023-2196 Missing permission checks in Code Dx Plugin — Jenkins Code Dx Plugin 4.3 Medium2023-05-16
CVE-2023-31131 Arbitrary File Write when Extracting Tarballs in greenplum-db — gpdb 7.4 High2023-05-15
CVE-2023-32309 Arbitrary file inclusion with the pymdowm-snippets extension — pymdown-extensions 7.5 High2023-05-15
CVE-2023-31166 Improper Limitation of a Pathname to a Restricted Directory — SEL-3505 4.1 Medium2023-05-10
CVE-2023-26126 m.static 路径遍历漏洞 — m.static 7.5 High2023-05-10
CVE-2023-29128 Siemens SIMATIC Cloud Connect 路径遍历漏洞 — SIMATIC Cloud Connect 7 CC712 3.8 Low2023-05-09
CVE-2023-29104 Siemens SIMATIC Cloud Connect 路径遍历漏洞 — SIMATIC Cloud Connect 7 CC712 6.0 Medium2023-05-09
CVE-2023-27409 Siemens SCALANCE 路径遍历漏洞 — SCALANCE LPE9403 2.5 Low2023-05-09
CVE-2023-28127 Ivanti Avalanche 路径遍历漏洞 — Avalanche 7.5 -2023-05-09
CVE-2023-30855 Pimcore Path Traversal Vulnerability in AdminBundle/Controller/Reports/CustomReportController.php — pimcore 6.5 Medium2023-05-08
CVE-2023-31181 WJJ Software - InnoKB Server, InnoKB/Console 2.2.1 - CWE-22: Path Traversal — InnoKB Server, InnoKB/Console 7.5 High2023-05-08
CVE-2023-31179 AgilePoint NX v8.0 SU2.2 & SU2.3 - Path traversal — NX 6.5 Medium2023-05-08
CVE-2017-20184 Carlo Gavazzi Powersoft prone to Path Traversal — Powersoft 7.5 High2023-05-04
CVE-2023-28406 BIG-IP Configuration utility vulnerability — BIG-IP 4.3 Medium2023-05-03
CVE-2015-10105 IP Blacklist Cloud Plugin CSV File Import ip_blacklist_cloud.php valid_js_identifier path traversal — IP Blacklist Cloud Plugin 6.3 Medium2023-05-01
CVE-2023-30852 Pimcore Arbitrary File Read in Admin JS CSS files — pimcore 4.4 Medium2023-04-27
CVE-2023-24836 SUNNET CTMS - Path Traversal — CTMS 8.8 High2023-04-27
CVE-2023-22901 ChangingTec MOTP - Path Traversal — MOTP 4.9 Medium2023-04-27

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.