Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3355

3355 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-11615 Envolve Plugin <= 1.0 - Unauthenticated Language File Deletion — Envolve Plugin 5.3 Medium2025-05-05
CVE-2024-55913 IBM Concert Software path traversal — Concert Software 5.3 Medium2025-05-02
CVE-2025-4186 Wangshen SecGate 3600 g=route_ispinfo_export_save path traversal — SecGate 3600 6.3 Medium2025-05-02
CVE-2025-4185 Wangshen SecGate 3600 g=obj_area_export_save path traversal — SecGate 3600 6.3 Medium2025-05-01
CVE-2025-4178 xiaowei1118 java_server File Upload API FoodController.java path traversal — java_server 5.4 Medium2025-05-01
CVE-2025-4175 AlanBinu007 Spring-Boot-Advanced-Projects Upload Profile API Endpoint UserProfileController.java uploadUserProfileImage path traversal — Spring-Boot-Advanced-Projects 6.3 Medium2025-05-01
CVE-2025-46565 Vite's server.fs.deny bypassed with /. for files under project root — vite 6.5AIMediumAI2025-05-01
CVE-2025-27409 Joplin Server Vulnerable to Path Traversal — joplin 7.5 High2025-04-30
CVE-2025-4078 Wangshen SecGate 3600 g=log_export_file path traversal — SecGate 3600 4.3 Medium2025-04-29
CVE-2025-27937 SIOS Technology Quick Agent 路径遍历漏洞 — Quick Agent V3 6.5 -2025-04-27
CVE-2025-26692 SIOS Technology Quick Agent 路径遍历漏洞 — Quick Agent V3 9.8 -2025-04-27
CVE-2025-1565 Mayosis Core <= 5.4.1 - Unauthenticated Arbitrary File Read — Mayosis Core 7.5 High2025-04-25
CVE-2025-3300 WPMasterToolKit (WPMTK) – All in one plugin <= 2.5.2 - Authenticated (Administrator+) to Arbitrary File Read and Write — WPMasterToolKit (WPMTK) – All in one plugin 7.2 High2025-04-24
CVE-2025-3065 Database Toolset <= 1.8.4 - Unauthenticated Arbitrary File Deletion — Database Toolset 9.1 Critical2025-04-24
CVE-2025-34028 Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal — Command Center Innovation Release 9.8 -2025-04-22
CVE-2025-23250 NVIDIA Nemo Framework 路径遍历漏洞 — NeMo Framework 7.6 High2025-04-22
CVE-2025-3577 Zyxel AMG1302-T10B 安全漏洞 — AMG1302-T10B firmware 4.9 Medium2025-04-22
CVE-2025-32431 Traefik has a possible vulnerability with the path matchers — traefik 5.9 -2025-04-21
CVE-2025-3404 Download Manager <= 3.3.12 - Authenticated (Author+) Arbitrary File Deletion — Download Manager 8.8 High2025-04-19
CVE-2025-3520 Avatar <= 0.1.4 - Authenticated (Subscriber+) Arbitrary File Deletion — Avatar 8.1 High2025-04-18
CVE-2025-27283 WordPress Theme File Duplicator Plugin <= 1.3 - Arbitrary File Download vulnerability — Theme File Duplicator 6.5 Medium2025-04-17
CVE-2025-27299 WordPress MyTicket Events plugin <= 1.2.4 - Non-Arbitrary File Read vulnerability — MyTicket Events 5.3 Medium2025-04-17
CVE-2025-39568 WordPress StoreContrl Woocommerce plugin <= 4.1.3 - Arbitrary File Download Vulnerability — StoreContrl Woocommerce 7.5 High2025-04-17
CVE-2025-3294 WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Update — WP Editor 7.2 High2025-04-17
CVE-2025-3295 WP Editor <= 1.2.9.1 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read — WP Editor 4.9 Medium2025-04-17
CVE-2025-3686 misstt123 oasys show image path traversal — oasys 4.3 Medium2025-04-16
CVE-2025-32779 labsai/eddi Vulnerable to Path Traversal (Zip Slip) in ZIP Import Function — EDDI 6.5 Medium2025-04-15
CVE-2025-32943 PeerTube HLS Video Files Path Traversal 3.7 Low2025-04-15
CVE-2025-3562 Yonyou YonBIP userfile FileInputStream path traversal — YonBIP 4.3 Medium2025-04-14
CVE-2025-3547 frdel Agent-Zero get_work_dir_files path traversal — Agent-Zero 6.3 Medium2025-04-14

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3355 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.