Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3364

3364 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2024-5154 Cri-o: malicious container can create symlink on host 8.1 High2024-06-12
CVE-2024-4315 LFI Vulnerability due to Lack of Path Sanitization in parisneo/lollms — parisneo/lollms 9.8AICriticalAI2024-06-12
CVE-2024-37169 @jmondi/url-to-png arbitrary file read via Playwright's screenshot feature exploiting file wrapper — url-to-png 5.3 Medium2024-06-10
CVE-2024-36418 SuiteCRM authenticated RCE using connectors — SuiteCRM 8.6 High2024-06-10
CVE-2024-35754 WordPress Ovic Importer plugin <= 1.6.3 - Arbitrary File Download vulnerability — Ovic Importer 7.5 High2024-06-10
CVE-2024-35745 WordPress Strategery Migrations plugin <= 1.0 - Arbitrary File Deletion vulnerability — Strategery Migrations 7.5 High2024-06-10
CVE-2024-35744 WordPress Upunzipper plugin <= 1.0.0 - Arbitrary File Deletion vulnerability — Upunzipper 8.6 High2024-06-10
CVE-2024-35743 WordPress SC filechecker plugin <= 0.6 - Arbitrary File Deletion vulnerability — SC filechecker 8.6 High2024-06-10
CVE-2024-35712 WordPress Database Cleaner: Clean, Optimize & Repair plugin <= 1.0.5 - Arbitrary File Read vulnerability — Database Cleaner 4.9 Medium2024-06-10
CVE-2024-35677 WordPress MegaMenu plugin <= 2.3.12 - Unauthenticated Local File Inclusion vulnerability — MegaMenu 9.0 Critical2024-06-10
CVE-2024-35658 WordPress Checkout Field Editor for WooCommerce (Pro) plugin <= 3.6.2 - Unauthenticated Arbitrary File Deletion vulnerability — Checkout Field Editor for WooCommerce (Pro) 8.6 High2024-06-10
CVE-2024-34762 Wordpress Advanced Custom Fields Pro plugin < 6.2.10 - Contributor+ Local File Inclusion vulnerability — Advanced Custom Fields PRO 9.9 Critical2024-06-10
CVE-2024-32703 WordPress ARForms plugin <= 6.4 - Subscriber+ Arbitrary File Deletion vulnerability — ARForms 7.7 High2024-06-09
CVE-2024-32778 WordPress Contest Gallery plugin <= 21.3.4 - Arbitrary File Deletion vulnerability — Contest Gallery 8.5 High2024-06-09
CVE-2024-5187 Arbitrary File Overwrite in download_model_with_test_data in onnx/onnx — onnx/onnx 8.8AIHighAI2024-06-06
CVE-2024-3322 Path Traversal in parisneo/lollms-webui — parisneo/lollms-webui 9.3AICriticalAI2024-06-06
CVE-2024-1873 Path Traversal and Denial of Service in parisneo/lollms-webui — parisneo/lollms-webui 7.5AIHighAI2024-06-06
CVE-2024-3234 Path Traversal in gaizhenbiao/chuanhuchatgpt — gaizhenbiao/chuanhuchatgpt 7.5AIHighAI2024-06-06
CVE-2024-0520 Remote Code Execution due to Full Controlled File Write in mlflow/mlflow — mlflow/mlflow 9.8AICriticalAI2024-06-06
CVE-2024-5550 Exposure of Sensitive Information via Arbitrary System Path Lookup in h2oai/h2o-3 — h2oai/h2o-3 4.3AIMediumAI2024-06-06
CVE-2024-23793 Upload of files outside application directory — OTRS 6.3 Medium2024-06-06
CVE-2024-4941 Local File Inclusion in JSON component in gradio-app/gradio — gradio-app/gradio 7.5AIHighAI2024-06-06
CVE-2024-5505 NETGEAR ProSAFE Network Management System UpLoadServlet Directory Traversal Remote Code Execution Vulnerability — ProSAFE Network Management System 8.8AIHighAI2024-06-06
CVE-2024-28995 SolarWinds Serv-U L Directory Transversal Vulnerability — SolarWinds Serv-U 8.6 High2024-06-06
CVE-2024-5153 Startklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory Deletion — Startklar Elementor Addons 9.1 Critical2024-06-06
CVE-2024-5179 Cowidgets – Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion — Cowidgets – Elementor Addons 8.8 High2024-06-06
CVE-2024-35634 Woocommerce – Recent Purchases plugin <= 1.0.1 - File Inclusion vulnerability — Woocommerce – Recent Purchases 4.9 Medium2024-06-04
CVE-2024-34554 WordPress Stockholm Core plugin <= 2.4.1 - Local File Inclusion vulnerability — Stockholm Core 8.5 High2024-06-04
CVE-2024-34552 WordPress Stockholm theme <= 9.6 - Local File Inclusion vulnerability — Stockholm 8.5 High2024-06-04
CVE-2024-34551 WordPress Stockholm theme <= 9.6 - Unauthenticated Local File Inclusion vulnerability — Stockholm 9.0 Critical2024-06-04

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3364 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.