Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-8406 Path Traversal in zenml-io/zenml — zenml-io/zenml 9.8AICriticalAI2025-10-05
CVE-2025-47211 QTS, QuTS hero — QTS 6.5 -2025-10-03
CVE-2025-33034 Qsync Central — Qsync Central 7.5 -2025-10-03
CVE-2025-61666 Traccar Unauthenticated Local File Inclusion on Windows - Leakage of Traccar Config File — traccar 9.1AICriticalAI2025-10-02
CVE-2025-59744 Multiple vulnerabilities in AndSoft's e-TMS — e-TMS 5.3 -2025-10-02
CVE-2025-54293 Path Traversal in LXD Instance Log File Retrieval — LXD 6.5AIMediumAI2025-10-02
CVE-2025-54292 Client-Side Path Traversal in LXD-UI — LXD 8.1AIHighAI2025-10-02
CVE-2025-11221 Remote Code Execution in GTONE ChangeFlow — ChangeFlow 8.8 High2025-10-02
CVE-2025-11182 File Download in GTONE ChangeFlow — ChangeFlow 6.5 Medium2025-10-02
CVE-2025-58769 auth0-PHP: Improper File Type Handling in Bulk User Import — laravel-auth0 3.3 Low2025-10-01
CVE-2025-11233 Rust standard library didn't detect all path separators on Cygwin — std 9.8AICriticalAI2025-10-01
CVE-2025-8559 All in One Music Player <= 1.3.1 - Authenticated (Contributor+) Path Traversal via theme Parameter — All in One Music Player 6.5 Medium2025-09-30
CVE-2025-61586 FreshRSS is vulnerable to directory enumeration by setting path in its theme field — FreshRSS 5.3 -2025-09-29
CVE-2025-43813 Liferay Portal和Liferay DXP 路径遍历漏洞 — Portal 8.2AIHighAI2025-09-29
CVE-2025-11139 Bjskzy Zhiyou ERP com.artery.form.services.FormStudioUpdater uploadStudioFile path traversal — Zhiyou ERP 6.3 Medium2025-09-29
CVE-2025-11034 Dibo Data Decision Making System common_dep.action.jsp downloadImpTemplet path traversal — Data Decision Making System 4.3 Medium2025-09-26
CVE-2025-11031 DataTables examples.php path traversal — DataTables 5.3 Medium2025-09-26
CVE-2025-11018 Four-Faith Water Conservancy Informatization Platform download.do;usrlogout.do.do path traversal — Water Conservancy Informatization Platform 5.3 Medium2025-09-26
CVE-2025-11016 kalcaddle kodbox index.class.php fileOut path traversal — kodbox 4.3 Medium2025-09-26
CVE-2025-59002 WordPress BM Content Builder Plugin < 3.16.3.3 - Arbitrary File Deletion Vulnerability — BM Content Builder 7.7 High2025-09-26
CVE-2025-10307 Backuply – Backup, Restore, Migrate and Clone <= 1.4.8 - Authenticated (Admin+) Arbitrary File Deletion — Backuply – Backup, Restore, Migrate and Clone 6.5 Medium2025-09-26
CVE-2025-10951 geyang ml-logger server.py log_handler path traversal — ml-logger 7.3 High2025-09-25
CVE-2025-10449 Path Traversal in Saysis Computer Systems' Saysis Web Portal — Saysis Web Portal 8.6 High2025-09-25
CVE-2025-59343 tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball — tar-fs 7.5AIHighAI2025-09-24
CVE-2025-59825 astral-tokio-tar has a path traversal in tar extraction — tokio-tar 7.5 -2025-09-23
CVE-2025-9963 Path Traversal — P series (P07, P10, P12, P15) 9.8AICriticalAI2025-09-23
CVE-2025-10777 JSC R7 R7-Office Document Server downloadas path traversal — R7-Office Document Server 6.3 Medium2025-09-22
CVE-2025-10766 SeriaWei ZKEACMS EventViewerController.cs Download path traversal — ZKEACMS 4.3 Medium2025-09-21
CVE-2025-9079 Admin RCE via prepackaged plugins by way of misconfigured imports directory — Mattermost 8.0 High2025-09-19
CVE-2025-10709 Four-Faith Water Conservancy Informatization Platform historyDownload.do;otheruserLogin.do;getfile path traversal — Water Conservancy Informatization Platform 5.3 Medium2025-09-19

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.