Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-66262 Arbitrary File Overwrite via Tar Extraction Path Traversal — Mozart FM Transmitter 8.1AIHighAI2025-11-26
CVE-2025-66251 Unauthenticated Path Traversal with Arbitrary File Deletion — Mozart FM Transmitter 6.5AIMediumAI2025-11-26
CVE-2025-65952 Console is vulnerable to path traversal regarding custom assets — Console 6.5AIMediumAI2025-11-25
CVE-2025-34350 UnForm Server < 10.1.15 Doc Flow Unauthenticated File Read — UnForm Server 7.5AIHighAI2025-11-25
CVE-2025-59372 ASUS Router 安全漏洞 — Router 4.9AIMediumAI2025-11-25
CVE-2025-59366 ASUS Router 安全漏洞 — Router 9.8AICriticalAI2025-11-25
CVE-2025-34320 BASIS BBj < 25.00 Unauthenticated Arbitrary File Read RCE — BASIS BBj 9.1 -2025-11-20
CVE-2025-13435 Dreampie Resty HttpClient HttpClient.java request path traversal — Resty 5.6 Medium2025-11-20
CVE-2025-11001 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability — 7-Zip 8.8AIHighAI2025-11-19
CVE-2025-65025 esm.sh CDN service has arbitrary file write via tarslip — esm.sh 8.2 High2025-11-19
CVE-2025-64765 Astro middleware authentication checks based on url.pathname can be bypassed via url encoded values — astro 8.2AIHighAI2025-11-19
CVE-2025-64757 Astro Development Server is Vulnerable to Arbitrary Local File Read — astro 3.5 Low2025-11-19
CVE-2025-40549 SolarWinds Serv-U Path Restriction Bypass Vulnerability — Serv-U 9.1 Critical2025-11-18
CVE-2025-13266 wwwlike vlife VLifeApi SysFileApi.java create path traversal — vlife 5.3 Medium2025-11-17
CVE-2025-13265 lsfusion platform ZipUtils.java unpackFile path traversal — platform 6.3 Medium2025-11-17
CVE-2025-13262 lsfusion platform UploadFileRequestHandler.java UploadFileRequestHandler path traversal — platform 7.3 High2025-11-17
CVE-2025-13261 lsfusion platform DownloadFileRequestHandler.java DownloadFileRequestHandler path traversal — platform 5.3 Medium2025-11-17
CVE-2025-13246 shsuishang ShopSuite ModulithShop JwtAuthenticationFilter.java JwtAuthenticationFilter path traversal — ShopSuite ModulithShop 6.3 Medium2025-11-16
CVE-2025-36236 AIX Path Traversal — AIX 8.2 High2025-11-13
CVE-2025-12089 Data Tables Generator by Supsystic <= 1.10.45 - Authenticated (Admin+) Arbitrary File Deletion — Data Tables Generator by Supsystic 6.5 Medium2025-11-13
CVE-2016-15055 JVC VN-T IP-Camera Directory Traversal via check.cgi — IP-Camera (VN-T216VPRU) 7.5 -2025-11-12
CVE-2023-7327 Ozeki SMS Gateway <= 10.3.208 Unauthenticated Arbitrary File Read — Ozeki SMS Gateway 7.5 -2025-11-12
CVE-2025-11366 N-central Authentication bypass via path traversal — N-central 9.8 -2025-11-12
CVE-2025-11565 Schneider Electric PowerChute Serial Shutdown 安全漏洞 — PowerChute™ Serial Shutdown 6.8 -2025-11-12
CVE-2025-12382 Path Traversal Allows Remote Code Execution in AlgoSec Firewall Analyzer — Firewall Analyzer 8.8 -2025-11-12
CVE-2025-62449 Microsoft Visual Studio Code CoPilot Chat Extension Security Feature Bypass Vulnerability — Microsoft Visual Studio Code CoPilot Chat Extension 6.8 Medium2025-11-11
CVE-2025-60722 Microsoft OneDrive for Android Elevation of Privilege Vulnerability — OneDrive for Android 6.5 Medium2025-11-11
CVE-2025-11696 Studio 5000 ® Simulation Interface SSRF — Studio 5000® Simulation Interface™ 6.5 -2025-11-11
CVE-2025-42919 Information Disclosure vulnerability in SAP NetWeaver Application Server Java — SAP NetWeaver Application Server Java 5.3 Medium2025-11-11
CVE-2025-42894 Path Traversal vulnerability in SAP Business Connector — SAP Business Connector 6.8 Medium2025-11-11

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.