Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3353

3353 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-51453 IBM Sterling Secure Proxy directory traversal — Sterling Secure Proxy 4.3 Medium2025-05-28
CVE-2025-48744 SIGB PMB 路径遍历漏洞 — PMB 6.4 Medium2025-05-27
CVE-2025-5161 H3C SecCenter SMP-E1114P02 download operationDailyOut path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-26
CVE-2025-5160 H3C SecCenter SMP-E1114P02 download path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-26
CVE-2025-5159 H3C SecCenter SMP-E1114P02 download path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-25
CVE-2025-5158 H3C SecCenter SMP-E1114P02 downloadSoftware path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-25
CVE-2025-5157 H3C SecCenter SMP-E1114P02 fileContent path traversal — SecCenter SMP-E1114P02 4.3 Medium2025-05-25
CVE-2025-31053 WordPress KBx Pro Ultimate plugin < 8.0.5 - Arbitrary File Deletion Vulnerability — KBx Pro Ultimate 7.7 High2025-05-23
CVE-2025-46486 WordPress Nomupay Payment Processing Gateway plugin <= 7.1.7 - Arbitrary File Download Vulnerability — Nomupay Payment Processing Gateway 4.9 Medium2025-05-23
CVE-2025-46527 WordPress Web3Press – Decentralize Publishing with Writing NFT plugin <= 3.2.0 - Arbitrary File Read vulnerability — Web3Press 6.5 Medium2025-05-23
CVE-2025-47492 WordPress Drag and Drop File Upload for Elementor Forms plugin <= 1.4.3 - Arbitrary File Deletion Vulnerability — Drag and Drop File Upload for Elementor Forms 8.6 High2025-05-23
CVE-2025-47512 WordPress Tainacan plugin <= 0.21.14 - Arbitrary File Deletion vulnerability — Tainacan 8.6 High2025-05-23
CVE-2025-47513 WordPress Infocob CRM Forms plugin <= 2.4.0 - Arbitrary File Download vulnerability — Infocob CRM Forms 4.9 Medium2025-05-23
CVE-2025-47535 WordPress Opal Woo Custom Product Variation plugin <= 1.2.0 - Arbitrary File Deletion Vulnerability — Opal Woo Custom Product Variation 8.6 High2025-05-23
CVE-2025-47603 WordPress belingoGeo plugin <= 1.12.0 - Arbitrary File Download Vulnerability — belingoGeo 7.5 High2025-05-23
CVE-2025-48273 WordPress WP Job Portal plugin <= 2.3.2 - Arbitrary File Download Vulnerability — WP Job Portal 7.5 High2025-05-23
CVE-2025-4419 Hot Random Image <= 1.9.2 - Path Traversal to Authenticated (Contributor+) Limited Arbitrary Image Access via path Parameter — Hot Random Image 4.3 Medium2025-05-22
CVE-2025-3486 Allegra isZipEntryValide Directory Traversal Remote Code Execution Vulnerability — Allegra 8.8AIHighAI2025-05-22
CVE-2025-3884 Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability — Hue 7.5AIHighAI2025-05-22
CVE-2025-5029 Kingdee Cloud Galaxy Private Cloud BBC System File deleteFileAction.jhtml path traversal — Cloud Galaxy Private Cloud BBC System 5.4 Medium2025-05-21
CVE-2025-4524 Madara – Responsive and modern WordPress theme for manga sites <= 2.2.2 - Unauthenticated Local File Inclusion — Madara – Responsive and modern WordPress theme for manga sites 9.8 Critical2025-05-21
CVE-2025-48017 Improper Limitation of a Pathname to a Restricted Directory — SEL-5056 Software-Defined Network Flow Controller 9.0 Critical2025-05-20
CVE-2025-41229 VMware Cloud Foundation Directory Traversal Vulnerability — Cloud Foundation 8.2 High2025-05-20
CVE-2025-3223 WorkstationST EGD Configuration Server Path Traversal Vulnerability — WorkstationST 5.9 Medium2025-05-19
CVE-2025-32926 WordPress Grand Restaurant WordPress theme <= 7.0 - Path Traversal to PHP Object Injection vulnerability — Grand Restaurant 9.8 Critical2025-05-19
CVE-2025-27566 appleple a-blog cms 路径遍历漏洞 — a-blog cms 3.8 Low2025-05-19
CVE-2025-4912 SourceCodester Student Result Management System Image File update_student.php path traversal — Student Result Management System 5.4 Medium2025-05-19
CVE-2025-4898 SourceCodester Student Result Management System Logo File update_system.php unlink path traversal — Student Result Management System 5.4 Medium2025-05-18
CVE-2025-4893 jammy928 CoinExchange_CryptoExchange_Java File Upload Endpoint UploadFileUtil.java uploadLocalImage path traversal — CoinExchange_CryptoExchange_Java 6.3 Medium2025-05-18
CVE-2025-4868 merikbest ecommerce-spring-reactjs File Upload Endpoint admin path traversal — ecommerce-spring-reactjs 6.3 Medium2025-05-18

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3353 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.