Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-47921 Free Photo & Video Vault 0.0.2 Directory Traversal Vulnerability via Web Request — Free Photo & Video Vault - WiFi Transfe‪r 6.5 Medium2026-02-01
CVE-2022-50950 Webile 1.0.1 Directory Traversal Vulnerability via Web Application — Webile 6.5 Medium2026-02-01
CVE-2026-25069 SunFounder Pironman Dashboard <= 1.3.13 Path Traversal Arbitrary File Read/Deletion — Pironman Dashboard (pm_dashboard) 9.8AICriticalAI2026-01-31
CVE-2020-37041 OpenCTI 3.3.1 - Directory Traversal — OpenCTI 7.5 High2026-01-30
CVE-2020-37034 HelloWeb 2.0 - Arbitrary File Download — HelloWeb 7.5 High2026-01-30
CVE-2026-25152 @backstage/plugin-techdocs-node vulnerable to possible Path Traversal in TechDocs Local Generator — backstage 5.3 Medium2026-01-30
CVE-2026-0805 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller — Crafty Controller 8.2 High2026-01-30
CVE-2026-0963 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Crafty Controller — Crafty Controller 9.9 Critical2026-01-30
CVE-2026-25116 Runtipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path Traversal — runtipi 7.6 High2026-01-29
CVE-2026-24846 malcontent's archive extraction could write outside extraction directory — malcontent 5.5 Medium2026-01-29
CVE-2026-24687 Umbraco.Forms has path traversal and file enumeration vulnerability in Linux/Mac — Umbraco.Forms.Issues 4.9AIMediumAI2026-01-29
CVE-2020-37015 Ruijie Networks Switch eWeb S29_RGOS 11.4 - Directory Traversal — Ruijie Networks Switch eWeb S29_RGOS 7.5 High2026-01-29
CVE-2026-1616 osim: Path Traversal via query parameters in Nginx configuration — osim 7.5 High2026-01-29
CVE-2026-1588 jishenghua jshERP installByPath install path traversal — jshERP 2.7 Low2026-01-29
CVE-2026-1549 jishenghua jshERP PluginController uploadPluginConfigFile path traversal — jshERP 4.3 Medium2026-01-28
CVE-2026-24897 Authenticated Remote Code Execution via Arbitrary File Upload — Erugo 10.0 Critical2026-01-28
CVE-2026-1532 D-Link DCS-700L Music File Upload Service setUploadMusic uploadmusic path traversal — DCS-700L 2.4 Low2026-01-28
CVE-2020-36970 PMB 5.6 - 'chemin' Local File Disclosure — PMB Services 8.4 High2026-01-28
CVE-2026-1056 Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal — Snow Monkey Forms 9.8 Critical2026-01-28
CVE-2026-24842 node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal — node-tar 8.2 High2026-01-28
CVE-2026-24770 RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser — ragflow 9.8 Critical2026-01-27
CVE-2026-24741 ConvertX Vulnerable to Arbitrary File Deletion via Path Traversal in `POST /delete` — ConvertX 8.1 High2026-01-27
CVE-2020-36939 Cassandra Web 0.5.0 - Remote File Read — Cassandra Web 7.5 High2026-01-27
CVE-2026-24686 go-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository Names — go-tuf 4.7 Medium2026-01-27
CVE-2026-24479 HUSTOJ has Arbitrary File Write (Zip Slip) in Problem Import Modules that leads to RCE — hustoj 8.8AIHighAI2026-01-27
CVE-2026-24486 Python-Multipart has Arbitrary File Write via Non-Default Configuration — python-multipart 8.6 High2026-01-27
CVE-2026-24478 AnythingLLM vulnerable to Path Traversal — anything-llm 7.2 High2026-01-26
CVE-2026-24123 BentoML has a Path Traversal via Bentofile Configuration — BentoML 7.4 High2026-01-26
CVE-2026-24131 pnpm has Path Traversal via arbitrary file permission modification — pnpm 7.7AIHighAI2026-01-26
CVE-2026-24056 pnpm has symlink traversal in file:/git dependencies — pnpm 7.7AIHighAI2026-01-26

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.