Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3337

3337 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-33555 A vulnerability may allow remote attackers to read arbitrary files on the server of the WirelessHART-Gateway — WHA-GW-F2D2-0-AS- Z2-ETH 7.5 High2021-08-31
CVE-2021-37701 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links — node-tar 8.2 High2021-08-31
CVE-2021-37712 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links — node-tar 8.2 High2021-08-31
CVE-2021-24549 AceIDE <= 2.6.2 - Authenticated (admin+) Arbitrary File Access — AceIDE 4.9 -2021-08-23
CVE-2021-22933 Pulse Secure Pulse Connect Secure 路径遍历漏洞 — Pulse Connect Secure 6.5 -2021-08-16
CVE-2021-24363 Photo Gallery < 1.5.75 - File Upload Path Traversal — Photo Gallery by 10Web – Mobile-Friendly Image Gallery 4.9 -2021-08-16
CVE-2021-21501 ServiceComb ServiceCenter Directory Traversal — Apache ServiceComb 9.1 -2021-08-10
CVE-2021-34638 WordPress Download Manager <= 3.1.24 Authenticated Directory Traversal — WordPress Download Manager 6.5 Medium2021-08-05
CVE-2021-32804 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization — node-tar 8.2 High2021-08-03
CVE-2021-32803 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning — node-tar 8.2 High2021-08-03
CVE-2021-32814 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Skytable — skytable 8.8 High2021-08-03
CVE-2020-5370 DELL EMC OpenManage Enterprise 路径遍历漏洞 — OpenManage Enterprise 7.9 High2021-07-22
CVE-2021-35968 Learningdigital.com, Inc. Orca HCM - Path Traversal-2 — Orca HCM 4.3 Medium2021-07-19
CVE-2021-35967 Learningdigital.com, Inc. Orca HCM - Path Traversal-1 — Orca HCM 5.3 Medium2021-07-19
CVE-2021-24453 Include Me <= 1.2.1 - Authenticated Remote Code Execution (RCE) via LFI log poisoning — Include Me 8.8 -2021-07-19
CVE-2021-24447 WP Image Zoom < 1.47 - Local File Inclusion — WP Image Zoom 6.5 -2021-07-19
CVE-2021-32769 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core — micronaut-core 7.5 High2021-07-16
CVE-2021-35962 TAIWAN SECOM CO., LTD., Door Access Control and Personnel Attendance Management system - Path Traversal — Door Access Control and Personnel Attendance Management system 7.5 High2021-07-16
CVE-2021-32746 Possible path traversal by use of the `doc` module — icingaweb2 5.3 Medium2021-07-12
CVE-2021-32532 QSAN XEVO - Path Traversal — XEVO 7.5 High2021-07-07
CVE-2021-32527 QSAN Storage Manager - Path Traversal-2 — Storage Manager 7.5 High2021-07-07
CVE-2021-32516 QSAN Storage Manager - Path Traversal — Storage Manager 7.5 High2021-07-07
CVE-2021-24375 Motor theme < 3.1.0 - Local File Inclusion — Motor 9.8 -2021-07-06
CVE-2021-28588 Adobe RoboHelp Server folderId Directory Traversal Remote Code Execution Vulnerability — RoboHelp Server 8.8 High2021-06-28
CVE-2021-28584 Magento Commerce path traversal vulnerability in child theme store creation — Magento Commerce 5.4 Medium2021-06-28
CVE-2021-21102 Adobe Illustrator DOCX file parsing directory traversal vulnerability could lead to remote code execution — Illustrator 8.8 High2021-06-28
CVE-2021-21090 Adobe InCopy DOCX file parsing directory traversal vulnerability could lead to remote code execution — InCopy 8.8 High2021-06-28
CVE-2021-29087 Synology DiskStation Manager 路径遍历漏洞 — DiskStation Manager (DSM) 7.5 High2021-06-23
CVE-2021-32674 Remote Code Execution via traversal in TAL expressions — Zope 8.8 High2021-06-08
CVE-2021-32662 TechDocs mkdocs.yml path traversal — backstage 6.5 Medium2021-06-03

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3337 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.