Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3323

3323 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-6057 Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution — FalkorDB Browser 9.8 -2026-04-10
CVE-2026-6024 Tenda i6 HTTP R7WebsSecurityHandlerfunction path traversal — i6 7.3 High2026-04-10
CVE-2026-5998 zhayujie chatgpt-on-wechat CowAgent API Memory Content Endpoint service.py dispatch path traversal — chatgpt-on-wechat CowAgent 5.3 Medium2026-04-10
CVE-2026-4351 Perfmatters <= 2.5.9 - Authenticated (Subscriber+) Arbitrary File Overwrite via 'snippets' Parameter — Perfmatters 8.1 High2026-04-10
CVE-2026-40152 PraisonAIAgents has a Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary — PraisonAIAgents 5.3 Medium2026-04-09
CVE-2026-35206 Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment — helm 3.5AILowAI2026-04-09
CVE-2026-39977 flatpak-builder has a path traversal leading to arbitrary file read on host when installing licence files — flatpak-builder 7.5AIHighAI2026-04-09
CVE-2026-39981 AGiXT has a Path Traversal in safe_join() — AGiXT 8.8 High2026-04-09
CVE-2026-5962 Tenda CH22 httpd R7WebsSecurityHandlerfunction path traversal — CH22 7.3 High2026-04-09
CVE-2026-35204 Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory — helm 5.7AIMediumAI2026-04-09
CVE-2026-5849 Tenda i12 HTTP path traversal — i12 7.3 High2026-04-09
CVE-2026-5841 Tenda i3 HTTP R7WebsSecurityHandler path traversal — i3 7.3 High2026-04-09
CVE-2026-40027 ALEAPP NQ Vault Artifact Parser Path Traversal — ALEAPP 7.3 High2026-04-08
CVE-2026-40024 Sleuth Kit tsk_recover Path Traversal — sleuthkit 7.1 High2026-04-08
CVE-2026-5436 MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys — MW WP Form 8.1 High2026-04-08
CVE-2026-39844 NiceGUI has a Path Traversal in NiceGUI Upload Filename on Windows via Backslash Bypass of PurePosixPath Sanitization — nicegui 5.9 Medium2026-04-08
CVE-2026-39859 LiquidJS has a renderFile() / parseFile() bypass configured root and allow arbitrary file read — liquidjs 4.9AIMediumAI2026-04-08
CVE-2026-33466 Improper Limitation of a Pathname to a Restricted Directory in Logstash Leading to Arbitrary File Write — Logstash 8.1 High2026-04-08
CVE-2026-39408 Hono has a path traversal in toSSG() allows writing files outside the output directory — hono 7.5AIHighAI2026-04-08
CVE-2026-39407 Hono has a middleware bypass via repeated slashes in serveStatic — hono 5.3 Medium2026-04-08
CVE-2026-39406 @hono/node-server has a middleware bypass via repeated slashes in serveStatic — node-server 5.3 Medium2026-04-08
CVE-2026-3243 Advanced Members for ACF <= 1.2.5 - Authenticated (Subscriber+) Arbitrary File Deletion via Path Traversal — Advanced Members for ACF 8.8 High2026-04-08
CVE-2026-39847 Emmett has a path traversal in internal assets handler — emmett 9.1 Critical2026-04-07
CVE-2026-34079 Flatpak affected by arbitrary file deletion on the host filesystem — flatpak 7.1AIHighAI2026-04-07
CVE-2026-34371 LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal — LibreChat 6.3 Medium2026-04-07
CVE-2026-39369 WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs — AVideo 7.6 High2026-04-07
CVE-2026-39365 Vite has a Path Traversal in Optimized Deps `.map` Handling — vite 4.3 -2026-04-07
CVE-2026-39345 OrangeHRM Affected by Arbitrary File Read via Path Traversal in Email Template Loader — orangehrm 6.5AIMediumAI2026-04-07
CVE-2026-24147 NVIDIA Triton Inference Server 路径遍历漏洞 — Triton Inference Server 4.8 Medium2026-04-07
CVE-2026-35573 ChurchCRM has a Path traversal leads to RCE — CRM 9.1 Critical2026-04-07

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3323 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.