Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-22857 ChanGate EnterPrise Co., Ltd property management system - Directory Traversal — property management system 7.5 High2021-02-17
CVE-2020-29026 Secomea GateManager 路径遍历漏洞 — GateManager 9.0 Critical2021-02-15
CVE-2021-21037 Acrobat Reader DC Path Traversal Vulnerability Could Lead To Arbitrary Code Execution — Acrobat Reader 7.8 High2021-02-11
CVE-2021-22656 Advantech Iview 路径遍历漏洞 — Advantech iView 7.5 -2021-02-11
CVE-2020-27871 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 — Orion Platform 8.8 -2021-02-10
CVE-2020-27870 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 — Orion Platform 6.5 -2021-02-10
CVE-2020-26299 File System Bounds Escape — ftp-srv 6.3 Medium2021-02-10
CVE-2020-25237 SINEC NMS 路径遍历漏洞 — SINEC NMS 8.1 -2021-02-09
CVE-2021-21284 privilege escalation in Moby — moby 6.8 Medium2021-02-02
CVE-2020-15097 Path Traversal in loklak — loklak 9.1 Critical2021-02-02
CVE-2021-21272 zip slip in ORAS — oras 7.7 High2021-01-25
CVE-2020-26295 CMS Editor code execution — magento-lts 8.7 High2021-01-21
CVE-2020-26285 Widget instances allows a hacker to inject an executable file on the server on OpenMage — magento-lts 8.7 High2021-01-21
CVE-2020-26252 Layout XML RCE Vulnerability in OpenMage — magento-lts 8.7 High2021-01-20
CVE-2021-1259 Cisco SD-WAN vManage Software Path Traversal Vulnerability — Cisco SD-WAN vManage 6.5 -2021-01-20
CVE-2020-27859 NEC ESMPRO Manager 路径遍历漏洞 — ESMPRO Manager 7.5 -2021-01-20
CVE-2021-21269 Path Traversal in Keymaker — keymaker 7.7 High2021-01-20
CVE-2021-21251 ZipSlip Arbitrary File Upload — onedev 7.7 High2021-01-15
CVE-2020-29495 DELL Dell EMC Avamar Server 操作系统命令注入漏洞 — Avamar 10.0 Critical2021-01-14
CVE-2020-29494 DELL Dell EMC Avamar Server 路径遍历漏洞 — Avamar 8.7 High2021-01-14
CVE-2021-21234 Directory Traversal — spring-boot-actuator-logview 7.7 High2021-01-05
CVE-2020-2504 Absolute path traversal vulnerability in QES — QES 5.8 Medium2020-12-24
CVE-2020-7535 Schneider Electric Modicon M340 路径遍历漏洞 — Web Server on Modicon M340, Legacy Offers Modicon Quantum and Modicon Premium and associated Communication Modules (see security notification for affected versions) 7.5 -2020-12-11
CVE-2020-14366 Red Hat Keycloak 路径遍历漏洞 — keycloak 6.8 Medium2020-11-09
CVE-2020-3588 Cisco Webex Meetings Desktop App Arbitrary Code Execution Vulnerability — Cisco Webex Meetings Desktop App 7.3 High2020-11-06
CVE-2020-27128 Cisco SD-WAN vManage Software Arbitrary File Creation Vulnerability — Cisco SD-WAN vManage 6.5 Medium2020-11-06
CVE-2020-15703 aptdaemon allows unprivileged users to test for the presence of local files via the transaction Locale property — aptdaemon 4.0 Medium2020-10-31
CVE-2020-3550 Cisco Firepower Management Center Software and Firepower Threat Defense Software Directory Traversal Vulnerability — Cisco Firepower Management Center 8.1 -2020-10-21
CVE-2020-15229 Path traversal and files overwrite with unsquashfs — singularity 8.2 High2020-10-14
CVE-2020-15239 Directory Traversal in xmpp-http-upload — xmpp-http-upload 3.5 Low2020-10-06

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.