Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-2336 Path Traversal in pimcore/pimcore — pimcore/pimcore 6.5 -2023-04-27
CVE-2023-2273 Rapid7 Insight Agent Directory Traversal — Insight Agent 5.8 Medium2023-04-26
CVE-2023-25815 Git looks for localized messages in the wrong place — git 3.3 Low2023-04-25
CVE-2023-25652 "git apply --reject" partially-controlled arbitrary file write — git 7.5 High2023-04-25
CVE-2023-29200 contao/core-bundle has path traversal vulnerability in the file manager — contao 4.3 Medium2023-04-25
CVE-2023-30626 Jellyfin vulnerable to directory traversal and file write causing arbitrary code execution — jellyfin 8.8 High2023-04-24
CVE-2023-22914 Zyxel USG FLEX 路径遍历漏洞 — USG FLEX series firmware 7.2 High2023-04-24
CVE-2023-25508 NVIDIA DGX-1 路径遍历漏洞 — NVIDIA DGX servers 6.7 Medium2023-04-22
CVE-2023-30620 Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb — mindsdb 7.5 High2023-04-21
CVE-2023-30548 Path traversal vulnerability in gatsby-plugin-sharp — gatsby 4.3 Medium2023-04-17
CVE-2023-29004 Path Traversal Vulnerability in hap-wi/roxy-wi — roxy-wi 6.5 Medium2023-04-17
CVE-2023-1109 PHOENIX CONTACT: Directory Traversal Vulnerability in ENERGY AXC PU Web service — ENERGY AXC PU (1264327) 8.8 High2023-04-17
CVE-2022-47501 Apache OFBiz: Arbitrary file reading vulnerability — Apache OFBiz 7.5 -2023-04-14
CVE-2023-29186 Directory/Path Traversal vulnerability in SAP NetWeaver. — NetWeaver (BI CONT ADDON) 8.7 High2023-04-11
CVE-2023-27603 Apache Linkis Mangaer module engineConn material upload exists Zip Slip issue — Apache Linkis 9.8 -2023-04-10
CVE-2023-1956 SourceCodester Online Computer and Laptop Store Image path traversal — Online Computer and Laptop Store 5.4 Medium2023-04-08
CVE-2022-43771 Hitachi Vantara Pentaho Business Analytics Server - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Pentaho Business Analytics Server 6.5 Medium2023-04-03
CVE-2023-28833 Unrestricted filenames for logo or favicon as admin in the theming settings in nextcloud server — security-advisories 2.4 Low2023-03-30
CVE-2022-23522 Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdb — mindsdb 8.5 High2023-03-30
CVE-2023-27534 curl 路径遍历漏洞 — https://github.com/curl/curl 8.8 -2023-03-30
CVE-2022-2560 Enterprise Distributed Technologies CompleteFTP Server 路径遍历漏洞 — CompleteFTP 9.1 -2023-03-29
CVE-2022-36981 Ivanti Avalanche 路径遍历漏洞 — Avalanche 9.8 -2023-03-29
CVE-2022-36982 Ivanti Avalanche 路径遍历漏洞 — Avalanche 7.5 -2023-03-29
CVE-2023-0241 pgAdmin 路径遍历漏洞 — pgadmin 8.1 -2023-03-27
CVE-2018-25048 Codesys Runtime Improper Limitation of a Pathname — Control for BeagleBone 8.8 High2023-03-23
CVE-2022-3101 Red Hat OpenStack Platform 安全漏洞 — tripleo-ansible 5.5 -2023-03-23
CVE-2022-3146 Red Hat OpenStack Platform 安全漏洞 — tripleo-ansible 5.5 -2023-03-23
CVE-2023-26361 Adobe ColdFusion Directory Traversal Arbitrary file system read Vulnerability — ColdFusion 4.9 Medium2023-03-23
CVE-2023-27856 Rockwell Automation ThinManager ThinServer Path Traversal Download — ThinManager ThinServer 7.5 High2023-03-21
CVE-2023-27855 Rockwell Automation ThinManager ThinServer Path Traversal Upload — ThinManager ThinServer 9.8 Critical2023-03-21

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.