Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-27800 Zed has Zip Slip Path Traversal in Extension Archive Extraction — zed 7.4 High2026-02-25
CVE-2026-27819 Vikunja has Path Traversal in CLI Restore — vikunja 7.2 High2026-02-25
CVE-2026-26985 LORIS vulnerable to path traversal in electrophysiology_browser — Loris 8.1 High2026-02-25
CVE-2026-26984 LORIS media module vulnerable to remote code execution — Loris 8.8AIHighAI2026-02-25
CVE-2026-3188 feiyuchuixue sz-boot-parent API templates path traversal — sz-boot-parent 4.3 Medium2026-02-25
CVE-2026-27704 Dart SDK and Flutter SDK have Zip slip in Dart Pub package extraction — sdk 7.3AIHighAI2026-02-25
CVE-2026-27699 Basic FTP has Path Traversal Vulnerability in its downloadToDir() method — basic-ftp 9.1 Critical2026-02-25
CVE-2026-25785 MOTEX LanScope Endpoint Manager 路径遍历漏洞 — Lanscope Endpoint Manager (On-Premises) Sub-Manager Server 8.8AIHighAI2026-02-25
CVE-2026-3179 A path traversal vulnerability was found in the FTP Backup on the ADM. — ADM 6.5 -2026-02-25
CVE-2026-27606 Rollup 4 has Arbitrary File Write via Path Traversal — rollup 9.9 -2026-02-25
CVE-2026-24849 OpenEMR Arbitrary File Read Vulnerability — openemr 10.0 Critical2026-02-25
CVE-2026-27598 Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory — dagu 8.8 -2026-02-25
CVE-2026-27117 bit7z has a path traversal vulnerability — bit7z 5.5 Medium2026-02-24
CVE-2026-25891 Fiber has an Arbitrary File Read in Static Middleware on Windows — fiber 7.5AIHighAI2026-02-24
CVE-2026-25603 Path Traversal vulnerability in Linksys MR9600, Linksys MX4200 — MR9600 6.8AIMediumAI2026-02-24
CVE-2026-27483 MindsDB has Path Traversal in /api/files Leading to Remote Code Execution — mindsdb 8.8 High2026-02-24
CVE-2025-15589 MuYuCMS Template Management Template.php delete_dir_file path traversal — MuYuCMS 3.8 Low2026-02-24
CVE-2026-3067 HummerRisk Archive Extraction CommandUtils.java extractZip path traversal — HummerRisk 6.3 Medium2026-02-24
CVE-2026-25965 ImageMagick's policy bypass through path traversal allows reading restricted content despite secured policy — ImageMagick 8.6 High2026-02-24
CVE-2026-3051 DataLinkDC dinky Project Name GitRepository.java getProjectDir path traversal — dinky 6.3 Medium2026-02-24
CVE-2026-23521 Traccar vulnerable to Path Traversal and External Control of File Name or Path — traccar 6.5 Medium2026-02-23
CVE-2026-2953 Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal — UJCMS 5.4 Medium2026-02-22
CVE-2026-2864 feng_ha_ha/megagao ssm-erp/production_ssm PictureController.java pictureDelete path traversal — ssm-erp 5.4 Medium2026-02-21
CVE-2026-2863 feng_ha_ha/megagao ssm-erp/production_ssm FileServiceImpl.java deleteFile path traversal — ssm-erp 5.4 Medium2026-02-21
CVE-2026-2033 MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability — MLflow 9.8AICriticalAI2026-02-20
CVE-2026-27115 ADB Explorer is Vulnerable to Arbitrary Directory Deletion via Command-Line Argument — ADB-Explorer 7.1 High2026-02-20
CVE-2026-24953 WordPress Simple File List plugin <= 6.1.15 - Arbitrary File Download vulnerability — Simple File List 6.5 Medium2026-02-20
CVE-2025-69380 WordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Download vulnerability — Upload Files Anywhere 7.5 High2026-02-20
CVE-2025-69377 WordPress User Extra Fields plugin <= 17.0 - Arbitrary File Deletion vulnerability — User Extra Fields 7.7 High2026-02-20
CVE-2025-69379 WordPress Upload Files Anywhere plugin <= 2.8 - Arbitrary File Deletion vulnerability — Upload Files Anywhere 8.6 High2026-02-20

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.