Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3364

3364 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-38709 WordPress GD Rating System plugin <= 3.6 - Local File Inclusion vulnerability — GD Rating System 5.3 Medium2024-07-12
CVE-2024-38704 WordPress Team Manager plugin <= 2.1.12 - Local File Inclusion vulnerability — WordPress Team Manager 6.5 Medium2024-07-12
CVE-2024-37932 WordPress Woocommerce OpenPos plugin <= 6.4.4 - Unauthenticated Arbitrary File Deletion vulnerability — Woocommerce OpenPos 8.6 High2024-07-12
CVE-2024-37928 WordPress Jobmonster theme <= 4.7.0 - Unauthenticated Arbitrary File Deletion vulnerability — Jobmonster 8.6 High2024-07-12
CVE-2024-2602 Schneider Electric FoxRTU Station 路径遍历漏洞 — FoxRTU Station 7.3 High2024-07-11
CVE-2024-22377 PingFederate Runtime Node Path Traversal — PingFederate 5.3 Medium2024-07-09
CVE-2024-37513 WordPress WPCafe plugin <= 2.2.27 - Local File Inclusion vulnerability — WPCafe 8.5 High2024-07-09
CVE-2024-37501 WordPress Advanced Classifieds & Directory Pro plugin <= 3.1.3 - Local File Inclusion vulnerability — Advanced Classifieds & Directory Pro 8.5 High2024-07-09
CVE-2024-37499 WordPress Online Booking & Scheduling Calendar for WordPress plugin <= 4.4.2 - Local File Inclusion vulnerability — Online Booking & Scheduling Calendar for WordPress by vcita 6.5 Medium2024-07-09
CVE-2024-37497 WordPress JetThemeCore plugin < 2.2.1 - Subscriber+ Arbitrary File Deletion vulnerability — JetThemeCore 7.7 High2024-07-09
CVE-2024-37464 WordPress Beaver Builder Addons by WPZOOM plugin <= 1.3.5 - Local File Inclusion vulnerability — Beaver Builder Addons by WPZOOM 4.9 Medium2024-07-09
CVE-2024-37462 WordPress Ultimate Bootstrap Elements for Elementor plugin <= 1.4.2 - Local File Inclusion vulnerability — Ultimate Bootstrap Elements for Elementor 8.5 High2024-07-09
CVE-2024-37454 WordPress AWSM Team – Team Showcase Plugin plugin <= 1.3.1 - Local File Inclusion vulnerability — AWSM Team 6.5 Medium2024-07-09
CVE-2024-37419 WordPress Cowidgets – Elementor Addons plugin <= 1.1.1 - Local File Inclusion vulnerability — Cowidgets – Elementor Addons 7.5 High2024-07-09
CVE-2024-37268 WordPress Striking theme <= 2.3.4 - Local File Inclusion vulnerability — Striking 8.5 High2024-07-09
CVE-2024-37266 WordPress Tutor LMS plugin <= 2.7.1 - Path Traversal vulnerability — Tutor LMS 4.9 Medium2024-07-09
CVE-2024-37224 WordPress SP Project & Document Manager plugin <= 4.71 - Directory Traversal vulnerability — SP Project & Document Manager 7.5 High2024-07-09
CVE-2024-5456 Panda Video <= 1.4.0 - Authenticated (Contributor+) Local File Inclusion — Panda Video 8.8 High2024-07-09
CVE-2024-37547 WordPress Elementor Addons by Livemesh plugin <= 8.4.0 - Local File Inclusion vulnerability — Livemesh Addons for Elementor 6.5 Medium2024-07-06
CVE-2024-2385 Elementor Addons by Livemesh <= 8.4 - Authenticated (Contributor+) Limited Local File Inclusion via Widgets — Livemesh Addons by Elementor 8.8 High2024-07-04
CVE-2024-5821 Local File Inclusion (LFI) in stitionai/devika — stitionai/devika 9.1AICriticalAI2024-07-03
CVE-2024-5349 LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion — LA-Studio Element Kit for Elementor 8.8 High2024-07-02
CVE-2024-24749 Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat — geoserver 7.5 High2024-07-01
CVE-2023-47803 Synology Camera Firmware 路径遍历漏洞 — Camera Firmware 5.3 Medium2024-06-28
CVE-2024-6127 BC Security Empire Path Traversal RCE — Empire 9.8 Critical2024-06-27
CVE-2024-5980 Arbitrary File Write via /v1/runs API endpoint in lightning-ai/pytorch-lightning — lightning-ai/pytorch-lightning 8.8AIHighAI2024-06-27
CVE-2024-5824 Path Traversal in parisneo/lollms — parisneo/lollms 9.8AICriticalAI2024-06-27
CVE-2024-6085 Path Traversal in parisneo/lollms — parisneo/lollms 9.1AICriticalAI2024-06-27
CVE-2024-6090 Path Traversal Vulnerability in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 7.1AIHighAI2024-06-27
CVE-2024-5548 Directory Traversal in stitionai/devika — stitionai/devika 7.5AIHighAI2024-06-27

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3364 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.