Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3364

3364 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-46205 WordPress Ultimate Addons for WPBakery Page Builder plugin <= 3.19.14 - Local File Inclusion vulnerability — Ultimate Addons for WPBakery Page Builder 7.1 High2024-05-17
CVE-2023-46197 WordPress Popup by Supsystic plugin <= 1.10.19 - Unauthenticated Subscriber Email Addresses Disclosure — Popup by Supsystic 5.3 Medium2024-05-17
CVE-2023-45652 WordPress Remote Content Shortcode plugin <= 1.5 - Local File Inclusion vulnerability — Remote Content Shortcode 6.5 Medium2024-05-17
CVE-2023-39163 WordPress Phlox Shop plugin <= 2.0.0 - Unauthenticated Local File Inclusion vulnerability — Phlox Shop 8.6 High2024-05-17
CVE-2023-38399 WordPress Phlox Portfolio plugin <= 2.3.1 - Unauthenticated Local File Inclusion vulnerability — Phlox Portfolio 8.6 High2024-05-17
CVE-2023-37888 WordPress Phlox Core Elements plugin <= 2.14.0 - Unauthenticated Local File Inclusion vulnerability — Shortcodes and extra features for Phlox theme 7.6 High2024-05-17
CVE-2023-37385 WordPress Consulting theme <= 6.5.6 - Local File Inclusion — Consulting 7.3 High2024-05-17
CVE-2023-35881 WordPress WooCommerce One Page Checkout plugin <= 2.3.0 - Local File Inclusion vulnerability — WooCommerce One Page Checkout 7.6 High2024-05-17
CVE-2023-33310 WordPress Unite Gallery Lite plugin <= 1.7.59 - Local File Inclusion vulnerability — Unite Gallery Lite 6.0 Medium2024-05-17
CVE-2023-32297 WordPress LWS Affiliation plugin <= 2.2.6 - Local File Inclusion vulnerability — LWS Affiliation 9.0 Critical2024-05-17
CVE-2023-32110 WordPress JupiterX theme <= 3.0.0 - Auth. Local File Inclusion vulnerability — JupiterX 7.6 High2024-05-17
CVE-2023-26526 WordPress Bookly plugin <= 21.7.1 - Authenticated Arbitrary File Deletion vulnerability — Bookly 7.7 High2024-05-17
CVE-2023-25050 WordPress Shortcodes Ultimate plugin <= 5.12.6 - Arbitrary File Download vulnerability — Shortcodes Ultimate 7.1 High2024-05-17
CVE-2023-24379 WordPress Landing Page Builder – Free Landing Page Templates plugin <= 3.1.9.9 - Local File Inclusion vulnerability — Landing Page Builder – Free Landing Page Templates 6.8 Medium2024-05-17
CVE-2023-23888 WordPress Rank Math SEO plugin <= 1.0.107.2 - Local File Inclusion vulnerability — Rank Math SEO 7.6 High2024-05-17
CVE-2023-23872 WordPress GMAce plugin <= 1.5.2 - Arbitrary File Download vulnerability — GMAce 4.9 Medium2024-05-17
CVE-2023-23700 WordPress OceanWP theme <= 3.4.1 - Authenticated Local File Inclusion vulnerability — OceanWP 7.6 High2024-05-17
CVE-2022-45374 WordPress Yet Another Related Posts Plugin (YARPP) plugin <= 5.30.4 - Local File Inclusion — YARPP 7.7 High2024-05-17
CVE-2022-45368 WordPress 1003 Mortgage Application plugin <= 1.75 - Local File Inclusion — 1003 Mortgage Application 7.7 High2024-05-17
CVE-2024-34808 WordPress JCH Optimize plugin <= 4.2.0 - Path Traversal vulnerability — JCH Optimize 4.3 Medium2024-05-16
CVE-2024-4956 Nexus Repository 3 - Path Traversal — Nexus Repository 7.5 High2024-05-16
CVE-2024-3403 Local File Inclusion in imartinez/privategpt — imartinez/privategpt 9.1AICriticalAI2024-05-16
CVE-2024-3484 Path Traversal vulnerability found in iManager — iManager 5.7 Medium2024-05-15
CVE-2023-5938 Path traversal via 'zip slip' in Arc before v1.6.0 — Arc 8.0 High2024-05-15
CVE-2024-3318 SailPoint Identity Security Cloud Connector File Path Traversal Vulnerability — Identity Security Cloud 4.2 Medium2024-05-15
CVE-2024-32465 Git's protections for cloning untrusted repositories can be bypassed — git 7.4 High2024-05-14
CVE-2024-32002 Git's recursive clones on case-insensitive filesystems that support symlinks are susceptible to Remote Code Execution — git 9.1 Critical2024-05-14
CVE-2024-1630 Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component — Venue 7.7 High2024-05-14
CVE-2024-1629 Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component — Venue 6.2 Medium2024-05-14
CVE-2024-27946 Siemens RUGGEDCOM CROSSBOW 路径遍历漏洞 — RUGGEDCOM CROSSBOW 6.5 Medium2024-05-14

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3364 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.