Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3341

3341 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-31385 Junos OS: J-Web: A path traversal vulnerability allows an authenticated attacker to elevate their privileges to root — Junos OS 8.8 High2021-10-19
CVE-2021-41149 Improper sanitization of target names in tough — tough 8.2 High2021-10-19
CVE-2021-41131 Client metadata path-traversal in python-tuf — python-tuf 7.5 High2021-10-19
CVE-2021-41152 Path Traversal in Folder Component Leading to Local File Inclusion — OpenOLAT 7.7 High2021-10-18
CVE-2021-41151 Path Traversal in @backstage/plugin-scaffolder-backend — backstage 6.8 Medium2021-10-18
CVE-2021-40724 Adobe Acrobat Reader Android Abritrary Code Execution Vulnerability — Reader Mobile 7.8 High2021-10-15
CVE-2021-3874 Path Traversal in bookstackapp/bookstack — bookstackapp/bookstack 6.5 -2021-10-15
CVE-2021-33178 Nagios 路径遍历漏洞 — NagVis 8.1 -2021-10-14
CVE-2021-38452 Moxa MXview Network Management Software — MXview Network Management Software 7.5 High2021-10-12
CVE-2021-33726 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 7.5 -2021-10-12
CVE-2021-33725 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 9.1 -2021-10-12
CVE-2021-33724 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 9.1 -2021-10-12
CVE-2021-33722 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 4.9 -2021-10-12
CVE-2021-42013 Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773) — Apache HTTP Server 9.8 -2021-10-07
CVE-2021-41773 Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 — Apache HTTP Server 9.1 -2021-10-05
CVE-2021-41103 Insufficiently restricted permissions on plugin directories — containerd 7.8 -2021-10-04
CVE-2021-41294 ECOA BAS controller - Path Traversal-4 — ECS Router Controller ECS (FLASH) 9.1 Critical2021-09-30
CVE-2021-41293 ECOA BAS controller - Path Traversal-3 — ECS Router Controller ECS (FLASH) 7.5 High2021-09-30
CVE-2021-41291 ECOA BAS controller - Path Traversal-1 — ECS Router Controller ECS (FLASH) 7.5 High2021-09-30
CVE-2021-36286 Dell SupportAssist Client 后置链接漏洞 — SupportAssist Client Consumer 7.1 High2021-09-28
CVE-2021-24638 OMGF < 4.5.4 - Unauthenticated Path Traversal in REST API — OMGF | Host Google Fonts Locally 9.1 -2021-09-20
CVE-2021-3806 Path Traversal in Pardus Software Center — Pardus Software Center 5.3 Medium2021-09-18
CVE-2021-39208 WriteEntryToDirectory used for an archive extraction is vulnerable to partial path traversal. — sharpcompress 4.3 Medium2021-09-16
CVE-2021-23043 F5 BIG-IP 路径遍历漏洞 — BIG-IP 6.5 -2021-09-14
CVE-2021-37532 SAP Business One 路径遍历漏洞 — SAP Business One 4.3 -2021-09-14
CVE-2021-40357 Siemens Teamcenter Active Workspace 路径遍历漏洞 — Teamcenter Active Workspace V4.3 7.2 -2021-09-14
CVE-2021-37200 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 7.7 -2021-09-14
CVE-2021-38360 wp-publications <= 0.0 Local File Include — wp-publications 8.3 High2021-09-10
CVE-2021-25452 Samsung SMR 输入验证错误漏洞 — Samsung Mobile Devices 5.5 Medium2021-09-09
CVE-2021-22704 多款 Schneider Electric 产品路径遍历漏洞 — Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) 9.1 -2021-09-02

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3341 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.