Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3346

3346 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-14997 BuddyPress Xprofile Custom Field Types <= 1.2.8 - Authenticated (Subscriber+) Arbitrary File Deletion — BuddyPress Xprofile Custom Field Types 8.8 High2026-01-06
CVE-2026-0604 FastDup <= 2.7 - Authenticated (Contributor+) Path Traversal via 'dir_path' REST Parameter — FastDup – Fastest WordPress Migration & Duplicator 6.5 Medium2026-01-06
CVE-2025-69226 AIOHTTP allows for a brute-force leak of internal static filepath components — aiohttp 5.3 -2026-01-05
CVE-2025-68953 Certain Frappe requests are vulnerable to Path Traversal — frappe 7.5 High2026-01-05
CVE-2025-15449 cld378632668 JavaMall MinioController.java delete path traversal — JavaMall 5.4 Medium2026-01-05
CVE-2026-0571 yeqifu warehouse AppFileUtils.java createResponseEntity path traversal — warehouse 4.3 Medium2026-01-02
CVE-2026-21440 AdonisJS Path Traversal in Multipart File Handling — core 7.5 -2026-01-02
CVE-2025-59384 Qfiling — Qfiling 7.5 -2026-01-02
CVE-2025-59381 QTS, QuTS hero — QTS 4.9 -2026-01-02
CVE-2025-59380 QTS, QuTS hero — QTS 4.9 -2026-01-02
CVE-2025-53594 Qfinder Pro, Qsync, QVPN — Qfinder Pro Mac 5.5 -2026-01-02
CVE-2025-15432 yeqifu carRental com.yeqifu.sys.controller.FileController downloadShowFile.action downloadShowFile path traversal — carRental 5.3 Medium2026-01-02
CVE-2022-50796 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi — Impact/Pulse/First 9.8 Critical2025-12-30
CVE-2022-50792 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability — Impact/Pulse/First 7.5 High2025-12-30
CVE-2025-15245 D-Link DCS-850L Firmware Update Service uploadfirmware path traversal — DCS-850L 3.5 Low2025-12-30
CVE-2025-14728 Rapid7 Velociraptor Directory Traversal Vulnerability — Velociraptor 6.8 Medium2025-12-29
CVE-2025-15187 GreenCMS File DataController.class.php path traversal — GreenCMS 3.8 Low2025-12-29
CVE-2025-15066 Arbitrary File Download through Path Traversal in Innorix WP — Innorix WP 6.2 Medium2025-12-29
CVE-2025-15138 prasathmani TinyFileManager tinyfilemanager.php path traversal — TinyFileManager 4.7 Medium2025-12-28
CVE-2025-15076 Tenda CH22 public path traversal — CH22 7.3 High2025-12-25
CVE-2019-25258 LogicalDOC Enterprise 7.7.4 Multiple Post-Authentication Directory Traversal Vulnerabilities — LogicalDOC Enterprise 7.5 High2025-12-24
CVE-2019-25256 VideoFlow Digital Video Protection DVP 2.10 Authenticated Directory Traversal — Digital Video Protection DVP 6.5 Medium2025-12-24
CVE-2019-25246 Beward N100 H.264 VGA IP Camera M2.1.6 Authenticated File Disclosure — N100 H.264 VGA IP Camera 8.8 High2025-12-24
CVE-2018-25144 Microhard Systems IPn4G 1.1.0 Arbitrary File Access via Undocumented System Editor — Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Arbitrary File Attacks 8.4 High2025-12-24
CVE-2025-13699 MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution Vulnerability — MariaDB 9.8AICriticalAI2025-12-23
CVE-2025-13698 Deciso OPNsense diag_backup.php filename Directory Traversal Arbitrary File Creation Vulnerability — OPNsense 5.7AIMediumAI2025-12-23
CVE-2025-14413 Soda PDF Desktop CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability — Desktop 7.8AIHighAI2025-12-23
CVE-2025-14420 pdfforge PDF Architect CBZ File Parsing Directory Traversal Remote Code Execution Vulnerability — PDF Architect 7.8AIHighAI2025-12-23
CVE-2023-53962 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write — Impact/Pulse/First 7.5 High2025-12-22
CVE-2023-53979 MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities — MyBB 8.8 High2025-12-22

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3346 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.