Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3348

3348 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2022-29837 Path traversal Vulnerability in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi Devices — My Cloud Home 4.7 Medium2022-12-01
CVE-2022-3361 Ultimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Contributor+) Directory Traversal via Shortcodes — Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin 4.3 Medium2022-11-29
CVE-2022-4031 Simple:Press <= 6.8 - Authenticated (Admin+) Path Traversal to Arbitrary File Modification — Simple:Press Forum 3.8 Low2022-11-29
CVE-2022-4030 Simple:Press <= 6.8 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Deletion — Simple:Press Forum 8.1 High2022-11-29
CVE-2022-44635 Apache Fineract allowed an authenticated user to perform remote code execution due to path traversal — Apache Fineract 8.8 -2022-11-29
CVE-2022-41158 eyoom builder Remote Code Execution Vulnerability — eyoom builder 7.2 High2022-11-25
CVE-2022-40977 PILZ: PASvisu and PMI affected by ZipSlip — PASvisu 7.5 High2022-11-24
CVE-2022-40976 PILZ: Multiple products affected by ZipSlip — PAScal 5.5 Medium2022-11-24
CVE-2022-44749 Opening workflows from untrusted resources may override arbitrary file system contents — KNIME Analytics Platform 5.5 Medium2022-11-24
CVE-2022-44748 Uploading workflows to KNIME Server may override arbitrary file system contents — KNIME Server 7.1 High2022-11-24
CVE-2022-4065 cbeust testng XML File Parser JarFileUtils.java testngXmlExistsInJar path traversal — testng 5.5 Medium2022-11-19
CVE-2022-41840 WordPress Welcart eCommerce plugin <= 2.7.7 - Unauth. Directory Traversal vulnerability — Welcart e-Commerce (WordPress plugin) 7.5 High2022-11-18
CVE-2022-3090 Red Lion Controls Crimson 路径遍历漏洞 — Crimson 3.0 7.5 High2022-11-17
CVE-2022-41920 Zip slip in Lancet — lancet 6.3 Medium2022-11-17
CVE-2022-39347 Missing path sanitation with `drive` channel in FreeRDP — FreeRDP 2.6 Low2022-11-16
CVE-2022-3966 Ultimate Member Plugin Template class-shortcodes.php load_template pathname traversal — Ultimate Member Plugin 4.3 Medium2022-11-13
CVE-2022-3976 MZ Automation libiec61850 MMS File Services mms_client_files.c path traversal — libiec61850 5.5 Medium2022-11-13
CVE-2022-3939 lanyulei ferry API file.go path traversal — ferry 6.3 Medium2022-11-11
CVE-2022-3940 lanyulei ferry task.go path traversal — ferry 3.5 Low2022-11-11
CVE-2022-41607 ETIC Telecom Remote Access Server Path Traversal — Remote Access Server (RAS) 6.2 Medium2022-11-10
CVE-2022-43753 SUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownload — SUSE Linux Enterprise Module for SUSE Manager Server 4.2 4.3 Medium2022-11-10
CVE-2022-31255 SUMA/UYUNI directory path traversal vulnerability in CobblerSnipperViewAction — SUSE Linux Enterprise Module for SUSE Manager Server 4.2 4.3 Medium2022-11-10
CVE-2022-39037 FLOWRING Agentflow BPM - Path Traversal — Agentflow BPM 7.5 High2022-11-10
CVE-2022-38120 POWERCOM CO., LTD. UPSMON PRO - Path Traversal — UPSMON PRO 6.5 Medium2022-11-10
CVE-2022-29836 Post-Auth Path Traversal Vulnerability Allows to Custom Package Installation via HTTP API — My Cloud Home 1.9 Low2022-11-09
CVE-2022-41212 SAP NetWeaver和SAP NetWeaver Application Server 路径遍历漏洞 — SAP NetWeaver Application Server ABAP and ABAP Platform 4.9 -2022-11-08
CVE-2020-12509 s::can moni::tools prone to path traversal in camera-file module — moni::tools 7.5 High2022-11-07
CVE-2020-12508 s::can moni::tools prone to path traversal in image-relocator module — moni::tools 7.5 High2022-11-07
CVE-2022-2711 WP All Import < 3.6.9 - Admin+ Directory traversal via file upload — Import any XML or CSV File to WordPress 7.2 -2022-11-07
CVE-2022-37866 Apache Ivy allows path traversal in the presence of a malicious repository — Apache Ivy 7.5 -2022-11-07

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3348 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.