Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3344

3344 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-35492 Kedro-Datasets has a path traversal vulnerability in PartitionedDataset allows arbitrary file write — kedro-plugins 6.5 Medium2026-04-07
CVE-2026-35487 text-generation-webui has a Path Traversal in load_prompt() — .txt file read without authentication — text-generation-webui 5.3 Medium2026-04-07
CVE-2026-35485 text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without authentication — text-generation-webui 7.5 High2026-04-07
CVE-2026-35484 text-generation-webui has a Path Traversal in load_preset() — .yaml file read without authentication — text-generation-webui 5.3 Medium2026-04-07
CVE-2026-35483 text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file read without authentication — text-generation-webui 5.3 Medium2026-04-07
CVE-2026-33227 Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory — Apache ActiveMQ Client 6.5AIMediumAI2026-04-07
CVE-2026-35454 Code Extension Marketplace has a Zip Slip Path Traversal — code-marketplace 6.2AIMediumAI2026-04-06
CVE-2026-35471 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs — goshs 9.1AICriticalAI2026-04-06
CVE-2026-35393 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs POST multipart upload — goshs 9.8AICriticalAI2026-04-06
CVE-2026-35392 goshs has an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs PUT Upload — goshs 9.1AICriticalAI2026-04-06
CVE-2026-35177 Path traversal issue with zip.vim in Vim — vim 4.1 Medium2026-04-06
CVE-2026-35174 Chyrp Lite has a Path Traversal to Remote Code Execution — chyrp-lite 9.1 Critical2026-04-06
CVE-2026-35167 Kedro has a path traversal in versioned dataset loading via unsanitized version string — kedro 7.1 High2026-04-06
CVE-2026-35050 text-generation-webui affected by Remote Code Execution (RCE) through Path Traversal at "Session -> Save extention settings to user_data/settings.yaml". — text-generation-webui 9.1 Critical2026-04-06
CVE-2026-34783 Ferret has a Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites — ferret 8.1 High2026-04-06
CVE-2026-5638 HerikLyma CPPWebFramework path traversal — CPPWebFramework 5.3 Medium2026-04-06
CVE-2026-5597 griptape-ai griptape ComputerTool tool.py path traversal — griptape 6.3 Medium2026-04-05
CVE-2019-25687 Pegasus CMS 1.0 Remote Code Execution via extra_fields.php — Pegasus CMS 9.8 Critical2026-04-05
CVE-2019-25671 VA MAX 8.3.4 Remote Code Execution via changeip.php — VA MAX 8.8 High2026-04-05
CVE-2026-5595 griptape-ai griptape FileManagerTool save_memory_artifacts_to_disk path traversal — griptape 6.3 Medium2026-04-05
CVE-2026-5535 FedML-AI FedML MQTT Message FileUtils.java path traversal — FedML 4.3 Medium2026-04-05
CVE-2026-3666 wpForo Forum <= 2.4.16 - Authenticated (Subscriber+) Arbitrary File Deletion via Post Body — wpForo Forum 8.8 High2026-04-04
CVE-2026-34607 Emlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCE — emlog 7.2 High2026-04-03
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) — cups 6.5 Medium2026-04-03
CVE-2026-26058 Zulip: Path Traversal in Import — zulip 6.1 Medium2026-04-03
CVE-2026-22661 prompts.chat Path Traversal via Skill File Handling — prompts.chat 8.1 High2026-04-03
CVE-2026-35214 Budibase: Path traversal in plugin file upload enables arbitrary directory deletion and file write — budibase 8.7 High2026-04-03
CVE-2026-4350 Perfmatters <= 2.5.9.1 - Authenticated (Subscriber+) Arbitrary File Deletion via 'delete' Parameter — Perfmatters 8.1 High2026-04-03
CVE-2026-34745 Unauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/public — fireshare 9.1 Critical2026-04-02
CVE-2026-34730 Copier `_external_data` allows path traversal and absolute-path local file read without unsafe mode — copier 5.5 Medium2026-04-02

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3344 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.