Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3357

3357 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-25223 LuxSoft LuxCal Web Calendar 路径遍历漏洞 — The LuxCal Web Calendar 7.5 -2025-02-18
CVE-2025-26779 WordPress Keep Backup Daily plugin <= 2.1.0 - Arbitrary File Download vulnerability — Keep Backup Daily 4.9 Medium2025-02-16
CVE-2025-1357 Seventh D-Guard HTTP GET Request path traversal — D-Guard 4.3 Medium2025-02-16
CVE-2025-1336 CmsEasy image_admin.php deleteimg_action path traversal — CmsEasy 4.3 Medium2025-02-16
CVE-2025-1335 CmsEasy file_admin.php deleteimg_action path traversal — CmsEasy 4.3 Medium2025-02-16
CVE-2025-25295 Label Studio has a Path Traversal Vulnerability via image Field — label-studio 7.5 -2025-02-14
CVE-2024-56477 IBM Power Hardware Management Console directory traversal — Power Hardware Management Console 6.5 Medium2025-02-14
CVE-2025-1127 Combination Path Traversal and Concurrent Execution vulnerability exists within the embedded web server — CX, XC, CS, MS, MX, XM, et. al. 9.1 Critical2025-02-13
CVE-2025-24889 Path traversal in sd-log Qubes virtual machine — securedrop-client 4.5 Medium2025-02-13
CVE-2025-24888 Path traversal in SecureDrop Client API.download_reply() — securedrop-client 8.1 High2025-02-13
CVE-2024-47266 Synology Active Backup for Business 路径遍历漏洞 — Active Backup for Business 2.7 Low2025-02-13
CVE-2024-47264 Synology Active Backup for Business 路径遍历漏洞 — Active Backup for Business 4.9 Medium2025-02-13
CVE-2024-10763 Campress <= 1.35 - Unauthenticated Local File Inclusion — Campress 9.8 Critical2025-02-13
CVE-2025-1228 olajowon Loggrove Logfile Update page path traversal — Loggrove 4.3 Medium2025-02-12
CVE-2024-11343 Telerik Document Processing Path Traversal — Telerik Document Processing Libraries 8.3 High2025-02-12
CVE-2025-0332 Progress UI for WinForms decompression path traversal vulnerability — Progress® Telerik® UI for WinForms 7.8 High2025-02-12
CVE-2025-24406 Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) — Adobe Commerce 7.5 High2025-02-11
CVE-2024-36508 Fortinet FortiManager和Fortinet FortiAnalyzer 路径遍历漏洞 — FortiManager 5.9 Medium2025-02-11
CVE-2024-11771 Ivanti CSA 路径遍历漏洞 — Cloud Services Application 5.3 Medium2025-02-11
CVE-2025-25243 Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) — SAP Supplier Relationship Management (Master Data Management Catalog) 8.6 High2025-02-11
CVE-2024-8685 Path-Traversal vulnerability in Revolution Pi — Revolution Pi 4.3 Medium2025-02-10
CVE-2025-1106 CmsEasy database_admin.php restore_action path traversal — CmsEasy 5.4 Medium2025-02-07
CVE-2025-25163 WordPress Plugin A/B Image Optimizer Plugin <= 3.3 - Arbitrary File Download vulnerability — Plugin A/B Image Optimizer 7.5 High2025-02-07
CVE-2025-25155 WordPress Music Sheet Viewer plugin <= 4.1 - Arbitrary File Read vulnerability — Music Sheet Viewer 7.5 High2025-02-07
CVE-2025-0859 Post and Page Builder by BoldGrid <= 1.27.6 - Path Traversal to Authenticated (Contributor+) Arbitrary File Read via template_via_url Function — Post and Page Builder by BoldGrid – Visual Drag and Drop Editor 6.5 Medium2025-02-06
CVE-2025-0799 IBM App Connect Enterprise Arbitrary File Write — IBM App Connect Enterprise 6.5 Medium2025-02-06
CVE-2025-22601 Client Side Path Traversal using activate account route in Discourse — discourse 3.1 Low2025-02-04
CVE-2025-24963 Browser mode serves arbitrary files in vitest — vitest 5.9 Medium2025-02-04
CVE-2024-48019 Apache Doris: allows admin users to read arbitrary files through the REST API — Apache Doris 4.9 -2025-02-04
CVE-2025-24960 Missing Input validation for filename in backups endpoint in Jellystat — Jellystat 8.7 High2025-02-03

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3357 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.