Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3362

3362 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-0799 IBM App Connect Enterprise Arbitrary File Write — IBM App Connect Enterprise 6.5 Medium2025-02-06
CVE-2025-22601 Client Side Path Traversal using activate account route in Discourse — discourse 3.1 Low2025-02-04
CVE-2025-24963 Browser mode serves arbitrary files in vitest — vitest 5.9 Medium2025-02-04
CVE-2024-48019 Apache Doris: allows admin users to read arbitrary files through the REST API — Apache Doris 4.9 -2025-02-04
CVE-2025-24960 Missing Input validation for filename in backups endpoint in Jellystat — Jellystat 8.7 High2025-02-03
CVE-2025-24961 Insecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3Proxy — s3proxy 7.5 -2025-02-03
CVE-2025-24605 WordPress WOLF plugin <= 1.0.8.5 - Path Traversal vulnerability — WOLF 7.5 Medium2025-02-03
CVE-2025-24569 WordPress PDF Generator Addon for Elementor Page Builder plugin <= 1.7.5 - Arbitrary File Read vulnerability — PDF Generator Addon for Elementor Page Builder 7.5 High2025-02-03
CVE-2025-23819 WordPress WP Cloud plugin <= 1.4.3 - Arbitrary File Deletion vulnerability — WP Cloud 7.5 High2025-02-03
CVE-2025-0973 CmsEasy index.php backAll_action path traversal — CmsEasy 5.4 Medium2025-02-03
CVE-2025-0365 Jupiterx Core <= 4.8.7 - Authenticated (Contributor+) Arbitrary File Read — Jupiter X Core 6.5 Medium2025-02-01
CVE-2025-24891 Dumb Drop has an arbitrary file overwrite and path traversal for root shell — DumbDrop 9.7 Critical2025-01-31
CVE-2025-0493 MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticated Limited Local File Inclusion — MultiVendorX – WooCommerce Multivendor Marketplace Solutions 9.8 Critical2025-01-31
CVE-2025-0572 Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability — PACS Server 6.5 -2025-01-30
CVE-2025-0573 Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability — PACS Server 7.5 -2025-01-30
CVE-2024-13671 Music Sheet Viewer <= 4.1 - Unauthenticated Arbitrary File Read — Music Sheet Viewer 7.5 High2025-01-30
CVE-2025-0750 Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting 6.6 Medium2025-01-28
CVE-2024-45598 Cacti has a Local File Inclusion (LFI) Vulnerability via Poller Standard Error Log Path — cacti 6.0 Medium2025-01-27
CVE-2023-38012 IBM Cloud Pak System directory traversal — Cloud Pak System 5.3 Medium2025-01-25
CVE-2024-13550 ABC Notation <= 6.1.3 - Authenticated (Contributor+) Arbitrary File Read — ABC Notation 6.5 Medium2025-01-25
CVE-2024-12885 Connections Business Directory <= 10.4.66 - Authenticated (Admin+) Arbitrary Directory Deletion — Connections Business Directory 6.5 Medium2025-01-25
CVE-2025-0703 JoeyBling bootplus SysFileController.java path traversal — bootplus 4.3 Medium2025-01-24
CVE-2025-24611 WordPress Export All Posts, Products, Orders, Refunds & Users Plugin <= 2.9 - Arbitrary File Read vulnerability — WP Ultimate Exporter 4.9 Medium2025-01-24
CVE-2024-13409 Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget <= 1.6.10 - Authenticated (Contributor+) Local File Inclusion via post_type_ajax_handler() — Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget 7.5 High2025-01-24
CVE-2025-23422 WordPress Store Locator plugin <= 3.98.10 - Local File Inclusion vulnerability — Store Locator 7.5 High2025-01-24
CVE-2024-13545 Bootstrap Ultimate <= 1.4.9 - Unauthenticated Limited Local File Inclusion — Bootstrap Ultimate 9.8 Critical2025-01-24
CVE-2024-42187 HCL BigFix Patch Download Plug-ins are affected by path traversal vulnerability — BigFix Patch Management Download Plug-ins 5.3 Medium2025-01-23
CVE-2025-23562 WordPress XLSXviewer plugin <= 2.1.1 - Arbitrary File Deletion vulnerability — XLSXviewer 7.5 Medium2025-01-22
CVE-2025-24019 YesWiki vulnerable to authenticated arbitrary file deletion — yeswiki 7.1 High2025-01-21
CVE-2025-0615 Input validation vulnerability in Qualifio's Wheel of Fortune — Wheel of fortune 5.3 Medium2025-01-21

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3362 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.