Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3363

3363 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-51483 changedetection.io Path Traversal vulnerability — changedetection.io 6.5AIMediumAI2024-11-01
CVE-2024-37108 WordPress WishList Member X plugin < 3.26.7 - Authenticated Arbitrary File Deletion vulnerability — WishList Member X 7.7 High2024-11-01
CVE-2024-37423 WordPress Newspack Blocks plugin <= 3.0.8 - Contributor+ Arbitrary Directory Deletion vulnerability — Newspack Blocks 8.5 High2024-11-01
CVE-2024-10005 Consul L7 Intentions Vulnerable To URL Path Bypass — Consul 8.1 High2024-10-30
CVE-2024-50508 WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Download vulnerability — Woocommerce Product Design 7.5 High2024-10-30
CVE-2024-50509 WordPress Woocommerce Product Design plugin <= 1.0.0 - Arbitrary File Deletion vulnerability — Woocommerce Product Design 8.6 High2024-10-30
CVE-2024-5982 Path Traversal in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 9.8AICriticalAI2024-10-29
CVE-2024-49771 MPXJ has a Potential Path Traversal Vulnerability — mpxj 5.3 Medium2024-10-28
CVE-2024-49766 Werkzeug safe_join not safe on Windows — werkzeug 7.5 -2024-10-25
CVE-2024-10011 BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal — BuddyPress 8.1 High2024-10-25
CVE-2024-45842 Sharp MFP 安全漏洞 — Sharp Digital Full-color MFPs and Monochrome MFPs 5.3 Medium2024-10-25
CVE-2024-49760 OpenRefine has a path traversal in LoadLanguageCommand — OpenRefine 7.1 High2024-10-24
CVE-2024-48931 ZimaOS Arbitrary File Read via Parameter Manipulation — ZimaOS 7.5 High2024-10-24
CVE-2024-10313 iniNet Solutions SpiderControl SCADA PC HMI Editor Path Traversal — SpiderControl SCADA PC HMI Editor 8.0 High2024-10-24
CVE-2024-41717 Kieback&Peter DDC4000 Series Path Traversal — DDC4040e 9.8 Critical2024-10-22
CVE-2024-35308 Post-auth Arbitrary File Read in the Server Plugins Section — Pandora FMS 6.5AIMediumAI2024-10-22
CVE-2024-49366 Nginx UI's json field can construct a directory traversal payload, causing arbitrary files to be written — nginx-ui 9.8AICriticalAI2024-10-21
CVE-2024-49286 WordPress SSV Events plugin <= 3.2.7 - Local File Inclusion to RCE vulnerability — SSV Events 9.6 Critical2024-10-20
CVE-2024-10100 Path Traversal in binary-husky/gpt_academic — binary-husky/gpt_academic 7.5AIHighAI2024-10-17
CVE-2024-49285 WordPress SSV MailChimp plugin <= 3.1.5 - Local File Inclusion vulnerability — SSV MailChimp 7.5 High2024-10-17
CVE-2024-49287 WordPress PDF-Rechnungsverwaltung plugin <= 0.0.1 - Local File Inclusion vulnerability — PDF-Rechnungsverwaltung 7.5 High2024-10-17
CVE-2024-49315 WordPress FREE DOWNLOAD MANAGER plugin <= 1.0.0 - Arbitrary File Deletion vulnerability — FREE DOWNLOAD MANAGER 8.6 High2024-10-17
CVE-2024-49245 WordPress Ahime Image Printer plugin <= 1.0.0 - Arbitrary File Download vulnerability — Ahime Image Printer 7.5 High2024-10-16
CVE-2024-47351 WordPress MaxSlider plugin <= 1.2.3 - Local File Inclusion vulnerability — MaxSlider 7.5 High2024-10-16
CVE-2024-47645 WordPress WPOptin plugin <= 2.0.1 - Local File Inclusion vulnerability — Top Bar – PopUps – by WPOptin 7.5 High2024-10-16
CVE-2024-45711 SolarWinds Serv-U FTP Service Directory Traversal Remote Code Execution Vulnerability — Serv-U 7.5 High2024-10-16
CVE-2019-25213 Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read — Advanced Access Manager – Access Governance for WordPress 9.8 Critical2024-10-16
CVE-2024-48914 Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy — vendure 9.1 Critical2024-10-15
CVE-2024-9676 Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos) 6.5 Medium2024-10-15
CVE-2024-46898 SHIRASAGI 安全漏洞 — SHIRASAGI 7.5 -2024-10-15

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3363 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.