Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3364

3364 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-5019 WhatsUp Gold LoadCSSUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp Gold 5.3 Medium2024-06-25
CVE-2024-5018 WhatsUp Gold LoadUsingBasePath Directory Traversal Information Disclosure Vulnerability — WhatsUp Gold 5.3 Medium2024-06-25
CVE-2024-5017 WhatsUp Gold AppProfileImport path traversal vulnerability — WhatsUp Gold 6.5 Medium2024-06-25
CVE-2024-4498 Path Traversal and RFI Vulnerability in parisneo/lollms-webui — parisneo/lollms-webui 7.5AIHighAI2024-06-25
CVE-2024-4885 WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability — WhatsUp Gold 9.8 Critical2024-06-25
CVE-2024-32111 WordPress core < 6.5.5 - Auth. Arbitrary .html File Read (Windows Only) vulnerability — WordPress 5.0 Medium2024-06-25
CVE-2023-49793 Path traversal in `CodeChecker server` in the endpoint of `CodeChecker store` — codechecker 6.5 Medium2024-06-24
CVE-2024-37231 WordPress Salon booking system plugin <= 9.9 - Arbitrary File Deletion vulnerability — Salon booking system 8.6 High2024-06-24
CVE-2024-37092 WordPress Consulting Elementor Widgets plugin <= 1.3.0 - Local File Inclusion vulnerability — Consulting Elementor Widgets 8.5 High2024-06-24
CVE-2024-37089 WordPress Consulting Elementor Widgets plugin <= 1.3.0 - Unauthenticated Local File Inclusion vulnerability — Consulting Elementor Widgets 9.0 Critical2024-06-24
CVE-2024-35781 WordPress Word Balloon plugin <= 4.21.1 - Local File Inclusion vulnerability — Word Balloon 6.5 Medium2024-06-21
CVE-2024-35778 WordPress Slideshow SE plugin <= 2.5.17 - Auth. Limited Local File Inclusion vulnerability — Slideshow SE 6.5 Medium2024-06-21
CVE-2024-4098 Shariff Wrapper <= 4.6.13 - Unauthenticated Local File Inclusion — Shariff Wrapper 9.8 Critical2024-06-20
CVE-2024-5182 Path Traversal in mudler/localai — mudler/localai 7.5 -2024-06-19
CVE-2024-38358 Symlink bypasses filesystem sandbox in wasmer — wasmer 2.9 Low2024-06-19
CVE-2024-36117 Path traversal while serving Reposilite javadoc expanded files — reposilite 8.6 High2024-06-19
CVE-2024-36116 Path traversal in Reposilite javadoc file expansion — reposilite 7.5 High2024-06-19
CVE-2024-37902 Path thraversal in DeepJavaLibrary — djl 10.0 Critical2024-06-17
CVE-2024-6044 D-Link router - Arbitrary File Reading — G403 6.5 Medium2024-06-17
CVE-2024-2024 Folders Pro <= 3.0.2 - Authenticated(Author+) Arbitrary File Upload via handle_folders_file_upload — Folders Pro 8.8 High2024-06-14
CVE-2024-2023 Folders <= 3.0 and Folders Pro <= 3.0.2 - Directory Traversal via handle_folders_file_upload — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager 4.3 Medium2024-06-14
CVE-2024-27178 Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 7.2 High2024-06-14
CVE-2024-27177 Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 7.2 High2024-06-14
CVE-2024-27176 Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 7.2 High2024-06-14
CVE-2024-27174 insecure upload — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-27173 insecure upload — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-27145 Multiple Post-authenticated Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-27144 Pre-authenticated Remote Code Execution — Toshiba Tec e-Studio multi-function peripheral (MFP) 9.8 Critical2024-06-14
CVE-2024-34129 Acrobat Android : OverSecured Finding : Overwriting arbitrary files via attacker-controlled output file paths — Acrobat Mobile Sign Android 7.5 High2024-06-13
CVE-2024-37037 Schneider Electric SAGE RTUs 路径遍历漏洞 — Sage 1410 8.1 High2024-06-12

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3364 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.