Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-25732 NiceGUI's Path Traversal via Unsanitized FileUpload.name Enables Arbitrary File Write — nicegui 7.5 High2026-02-06
CVE-2026-25592 Semantic Kernel has an Arbitrary File Write via AI Agent Function Calling in .NET SDK — semantic-kernel 10.0 Critical2026-02-06
CVE-2026-25635 calibre has a Path Traversal Leading to Arbitrary File Write and Potential Code Execution — calibre 8.6 High2026-02-06
CVE-2026-25636 calibre has a Path Traversal Leading to Arbitrary File Corruption and Code Execution — calibre 8.2 High2026-02-06
CVE-2026-25640 Pydantic AI affected by Stored XSS via Path Traversal in Web UI CDN URL — pydantic-ai 7.1 High2026-02-06
CVE-2026-24135 Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update — gogs 8.1AIHighAI2026-02-06
CVE-2026-23633 Gogs has arbitrary file read/write via path traversal in Git hook editing — gogs 6.5 Medium2026-02-06
CVE-2026-1523 Path Traversal in Digitek from Grupo Azkoyen — Digitek ADT1100 7.5AIHighAI2026-02-05
CVE-2026-1246 ShortPixel Image Optimizer <= 6.4.2 - Authenticated (Editor+) Arbitrary File Read via 'loadFile' Parameter — ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF 4.9 Medium2026-02-05
CVE-2026-25539 SiYuan has Arbitrary File Write via /api/file/copyFile leading to RCE — siyuan 9.1 Critical2026-02-04
CVE-2026-25161 Alist vulnerable to Path Traversal in multiple file operation handlers — alist 8.8 High2026-02-04
CVE-2026-25145 melange has a path traversal in license-path which allows reading files outside workspace — melange 5.5 Medium2026-02-04
CVE-2026-24843 melange QEMU runner could write files outside workspace directory — melange 8.2 High2026-02-04
CVE-2025-64712 Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write — unstructured 9.8 Critical2026-02-04
CVE-2026-25055 n8n Arbitrary File Write on Remote Systems via SSH Node — n8n 10.0AICriticalAI2026-02-04
CVE-2025-15487 Code Explorer <= 1.4.6 - Authenticated (Administrator+) Arbitrary File Read via 'file' Parameter — Code Explorer 4.9 Medium2026-02-04
CVE-2026-1812 bolo-blog bolo-solo Filename BackupService.java importFromCnblogs path traversal — bolo-solo 6.3 Medium2026-02-03
CVE-2020-37088 School ERP Pro 1.0 - Arbitrary File Read — School ERP Pro 7.5 High2026-02-03
CVE-2020-37086 Easy Transfer 1.7 for iOS - Directory Traversal — Easy Transfer 6.2 Medium2026-02-03
CVE-2020-37077 Booked Scheduler 2.7.7 - Authenticated Directory Traversal — Booked Scheduler 6.5 Medium2026-02-03
CVE-2026-1811 bolo-blog bolo-solo Filename BackupService.java importFromMarkdown path traversal — bolo-solo 6.3 Medium2026-02-03
CVE-2026-24053 Cluade Code has a Path Restriction Bypass via ZSH Clobber which Allows Arbitrary File Writes — claude-code 6.5AIMediumAI2026-02-03
CVE-2025-65077 Relative path traversal vulnerability in Embedded Solutions Framework — MXTCT, MSNGM, MSTGM, MXNGM, MXTGM, CSNGV, CSTGV, CXTGV, MSNGW, MSTGW, MXTGW, CSTLS, CXTLS, MXTLS, CSTMM, CXTMM, CSTPC, CXTPC, MXTPM, MSNSN, MSTSN, MXTSN, CSNZJ, CSTZJ, CXNZJ, CXTZJ 9.8AICriticalAI2026-02-03
CVE-2026-1810 bolo-blog bolo-solo ZIP File BackupService.java unpackFilteredZip path traversal — bolo-solo 6.3 Medium2026-02-03
CVE-2026-25228 SignalK Server has Path Traversal leading to information disclosure — signalk-server 5.0 Medium2026-02-02
CVE-2026-25059 OpenList affected by Path Traversal in file copy and remove handlers — OpenList 8.8 High2026-02-02
CVE-2025-66480 Wildfire has Arbitrary File Upload via Directory Traversal in UploadFileAction — im-server 9.8 Critical2026-02-02
CVE-2025-14914 IBM WebSphere Application Server Liberty Path Traversal — WebSphere Application Server Liberty 7.6 High2026-02-02
CVE-2026-1703 Limited path traversal when installing wheel archives — pip 7.7AIHighAI2026-02-02
CVE-2026-1186 Path Traversal in EAP Legislator — EAP Legislator 6.5AIMediumAI2026-02-02

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.