Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3363

3363 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-0129 NVIDIA NeMo 安全漏洞 — NeMo 6.3 Medium2024-10-15
CVE-2024-9047 WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deletion in wfu_file_downloader.php — Iptanus File Upload 9.8 Critical2024-10-12
CVE-2024-47877 Extract has insufficient checks allowing attacker to create symlinks outside the extraction directory. — extract 6.5AIMediumAI2024-10-11
CVE-2024-6971 Path Traversal in parisneo/lollms-webui — parisneo/lollms 8.4AIHighAI2024-10-11
CVE-2024-7514 WordPress Comments Import & Export <= 2.3.7 - Authenticated (Author+) Arbitrary File Read via Directory Traversal — Comments Import & Export 6.5 Medium2024-10-11
CVE-2024-47164 The `is_in_or_equal` function may be bypassed in Gradio — gradio 7.4AIHighAI2024-10-10
CVE-2024-47166 One-level read path traversal in `/custom_component` in Gradio — gradio 7.5AIHighAI2024-10-10
CVE-2024-7037 Arbitrary File Write/Delete Leading to RCE in open-webui/open-webui — open-webui/open-webui 9.8AICriticalAI2024-10-09
CVE-2024-9675 Buildah: buildah allows arbitrary directory mount 7.8 High2024-10-09
CVE-2024-9575 Local File Inclusion in pretix-widget WordPress plugin — pretix Widget WordPress plugin 9.1AICriticalAI2024-10-09
CVE-2024-47011 Ivanti Avalanche 安全漏洞 — Avalanche 7.5 High2024-10-08
CVE-2024-47010 Ivanti Avalanche 安全漏洞 — Avalanche 7.3 High2024-10-08
CVE-2024-47009 Ivanti Avalanche 安全漏洞 — Avalanche 7.3 High2024-10-08
CVE-2024-9381 Ivanti CSA 安全漏洞 — CSA (Cloud Services Appliance) 7.2 High2024-10-08
CVE-2024-47563 Siemens SINEC Security Monitor 路径遍历漏洞 — SINEC Security Monitor 5.3 Medium2024-10-08
CVE-2024-47818 Logged-in users with any role can delete arbitrary files in @saltcorn/server — saltcorn 6.5 Medium2024-10-07
CVE-2024-47559 Authenticated RCE via Path Traversal — FreeFlow Core 7.6 High2024-10-07
CVE-2024-47558 Authenticated RCE via Path Traversal — FreeFlow Core 7.6 High2024-10-07
CVE-2024-47557 Pre-Auth RCE via Path Traversal — FreeFlow Core 8.3 High2024-10-07
CVE-2024-47556 Pre-Auth RCE via Path Traversal — FreeFlow Core 8.3 High2024-10-07
CVE-2024-47309 WordPress Cities Shipping Zones for WooCommerce plugin <= 1.2.7 - Local File Inclusion vulnerability — Cities Shipping Zones for WooCommerce 6.6 Medium2024-10-05
CVE-2024-44034 WordPress WPSPX plugin <= 1.0.2 - Local File Inclusion vulnerability — WPSPX 7.5 High2024-10-05
CVE-2024-44018 WordPress Instant Chat WP plugin <= 1.0.5 - Local File Inclusion vulnerability — Instant Chat Floating Button for WordPress Websites 7.5 High2024-10-05
CVE-2024-44016 WordPress Podiant plugin <= 1.1 - Local File Inclusion vulnerability — Podiant 7.5 High2024-10-05
CVE-2024-44015 WordPress Users Control plugin <= 1.0.16 - Local File Inclusion vulnerability — Users Control 7.5 High2024-10-05
CVE-2024-44014 WordPress Vmax Project Manager plugin <= 1.0 - Local File Inclusion to RCE vulnerability — Vmax Project Manager 9.6 Critical2024-10-05
CVE-2024-44013 WordPress VR Calendar plugin <= 2.4.0 - Local File Inclusion vulnerability — VR Calendar 7.5 High2024-10-05
CVE-2024-44012 WordPress WP Newsletter Subscription plugin <= 1.1 - Local File Inclusion vulnerability — WP Newsletter Subscription 7.5 High2024-10-05
CVE-2024-44011 WordPress WP Ticket Ultra plugin <= 1.0.5 - Local File Inclusion vulnerability — WP Ticket Ultra Help Desk & Support Plugin 7.5 High2024-10-05
CVE-2024-9146 WordPress CSS JS Files plugin <= 1.5.0 - Directory Traversal to File Read vulnerability — CSS JS Files 4.9 Medium2024-10-05

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3363 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.