Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3323

3323 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-35496 CubeCart 安全漏洞 — CubeCart 4.9AIMediumAI2026-04-17
CVE-2026-4853 JetBackup <= 3.1.19.8 - Authenticated (Administrator+) Arbitrary Directory Deletion via Path Traversal in 'fileName' Parameter — JetBackup – Backup, Restore & Migrate 4.9 Medium2026-04-17
CVE-2026-6410 @fastify/static vulnerable to path traversal in directory listing — @fastify/static 5.3 Medium2026-04-16
CVE-2025-14868 Career Section <= 1.6 - Cross-Site Request Forgery to Arbitrary File Deletion — Career Section 8.8 High2026-04-16
CVE-2026-40503 OpenHarness Path Traversal Information Disclosure via /memory show — OpenHarness 6.5 Medium2026-04-16
CVE-2026-40256 Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision — weblate 5.0 Medium2026-04-15
CVE-2026-34242 Weblate: Arbitrary File Read via Symlink — weblate 7.7 High2026-04-15
CVE-2026-33220 Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository — weblate 6.8 Medium2026-04-15
CVE-2026-20180 Cisco Identity Services Engine Multiple Remote Code Execution Vulnerability — Cisco Identity Services Engine Software 9.9 Critical2026-04-15
CVE-2026-20148 Cisco Identity Services Engine Path Traversal Vulnerability — Cisco Identity Services Engine Software 4.9 Medium2026-04-15
CVE-2026-40090 Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write — zarf 7.1 High2026-04-14
CVE-2025-15470 Eleganzo <= 1.2 - Authenticated (Subscriber+) Arbitrary Directory Deletion — Eleganzo 6.5 Medium2026-04-14
CVE-2026-34619 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 7.7 High2026-04-14
CVE-2026-27305 ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — ColdFusion 8.6 High2026-04-14
CVE-2025-61624 Fortinet多款产品 路径遍历漏洞 — FortiOS 5.4 Medium2026-04-14
CVE-2025-68649 Fortinet多款产品 路径遍历漏洞 — FortiManager Cloud 5.4 Medium2026-04-14
CVE-2026-22573 Fortinet FortiSOAR PaaS和Fortinet FortiSOAR on-premise 路径遍历漏洞 — FortiSOAR on-premise 6.2 Medium2026-04-14
CVE-2026-25691 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox PaaS 6.2 Medium2026-04-14
CVE-2026-2399 Schneider Electric PowerChute Serial Shutdown 路径遍历漏洞 — PowerChute™ Serial Shutdown 6.5 -2026-04-14
CVE-2026-33929 Apache PDFBox Examples: Path Traversal in PDFBox ExtractEmbeddedFiles Example Code — Apache PDFBox Examples 7.5 -2026-04-14
CVE-2026-6227 BackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' Parameter — BackWPup – WordPress Backup & Restore Plugin 7.2 High2026-04-14
CVE-2026-22562 Ubiquiti UniFi Play PowerAmp和Ubiquiti UniFi Play Audio Port 安全漏洞 — UniFi Play PowerAmp 9.8 Critical2026-04-13
CVE-2026-32146 Improper Path Validation in Git Dependency Handling Allows Arbitrary File System Modification — Gleam 7.5 -2026-04-11
CVE-2026-3689 OpenClaw Canvas Path Traversal Information Disclosure Vulnerability — OpenClaw 6.5AIMediumAI2026-04-11
CVE-2026-40180 Zip Slip Path Traversal in quarkus-openapi-generator ApicurioCodegenWrapper class — quarkus-openapi-generator 9.1AICriticalAI2026-04-10
CVE-2026-31939 Path Traversal (Arbitrary File Delete) in Chamilo LMS — chamilo-lms 8.3 High2026-04-10
CVE-2026-40163 Saltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory read — saltcorn 8.2 High2026-04-10
CVE-2026-40157 PraisonAI affected by arbitrary file write via path traversal in `praisonai recipe unpack` — PraisonAI 8.1 -2026-04-10
CVE-2026-40086 Rembg has a Path Traversal via Custom Model Loading — rembg 5.3 Medium2026-04-10
CVE-2026-35668 OpenClaw < 2026.3.24 - Sandbox Media Root Bypass via Unnormalized mediaUrl and fileUrl Parameters — OpenClaw 7.7 High2026-04-10

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3323 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.