Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3344

3344 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-34726 Copier `_subdirectory` allows template root escape via parent-directory traversal — copier 4.4 Medium2026-04-02
CVE-2026-34591 Poetry Has Wheel Path Traversal Which Can Lead to Arbitrary File Write — poetry 7.8AIHighAI2026-04-02
CVE-2026-34524 SillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root — SillyTavern 8.3 High2026-04-02
CVE-2026-34523 SillyTavern: Path traversal allows file existence oracle — SillyTavern 5.3 Medium2026-04-02
CVE-2026-34522 SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory — SillyTavern 8.1 High2026-04-02
CVE-2026-34790 Endian Firewall /cgi-bin/backup.cgi remove ARCHIVE Directory Traversal — Endian Firewall 7.1 High2026-04-02
CVE-2026-5344 Textpattern XML-RPC TXP_RPCServer.php mt_uploadImage path traversal — Textpattern 6.3 Medium2026-04-02
CVE-2026-34728 phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController — phpMyFAQ 8.7 High2026-04-02
CVE-2026-5331 OpenCart Extension Installer installer.php path traversal — OpenCart 4.7 Medium2026-04-02
CVE-2026-4347 MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir — MW WP Form 8.1 High2026-04-02
CVE-2026-3987 WatchGuard Firebox Arbitrary File Write vis Path Traversal in Fireware Web UI — Fireware OS 7.2AIHighAI2026-04-01
CVE-2026-34750 Payload has Insufficient Filename Validation in Client-Upload Signed-URL Endpoints — payload 6.5 Medium2026-04-01
CVE-2026-34446 ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load — onnx 4.7 Medium2026-04-01
CVE-2026-20174 Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability — Cisco Nexus Dashboard 4.9 Medium2026-04-01
CVE-2026-34603 @tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions — tinacms 7.1 High2026-04-01
CVE-2026-34604 @tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions — tinacms 7.1 High2026-04-01
CVE-2026-33949 @tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files — tinacms 8.1 High2026-04-01
CVE-2026-27101 Dell Secure Connect Gateway 路径遍历漏洞 — Secure Connect Gateway 4.7 Medium2026-04-01
CVE-2026-5258 Sanster IOPaint File Manager file_manager.py _get_file path traversal — IOPaint 7.3 High2026-04-01
CVE-2026-34451 Claude SDK for TypeScript: Memory Tool Path Validation Allows Sandbox Escape to Sibling Directories — anthropic-sdk-typescript 8.1 -2026-03-31
CVE-2026-5203 CMS Made Simple UserGuide Module XML Import class.UserGuideImporterExporter.php _copyFilesToFolder path traversal — CMS Made Simple 4.7 Medium2026-03-31
CVE-2026-33581 OpenClaw < 2026.3.24 - Arbitrary File Read via mediaUrl and fileUrl Parameters — OpenClaw 6.5 Medium2026-03-31
CVE-2025-10559 Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025x — DELMIA Factory Resource Manager 7.1 High2026-03-31
CVE-2026-34070 LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions — langchain 7.5 High2026-03-31
CVE-2026-32727 SciTokens: Authorization Bypass via Path Traversal in Scope Validation — scitokens 8.1 High2026-03-31
CVE-2026-30940 baserCMS: Path Traversal in Theme File API Leads to Arbitrary File Write and RCE — basercms 7.2 High2026-03-31
CVE-2026-27018 Gotenberg: Chromium deny-list bypass via case-insensitive URL scheme — gotenberg 5.3 -2026-03-30
CVE-2026-33027 Nginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration Directory — nginx-ui 7.1 -2026-03-30
CVE-2026-5014 elecV2 elecV2P Wildcard log path.join path traversal — elecV2P 5.3 Medium2026-03-28
CVE-2026-5013 elecV2 elecV2P :key path.join path traversal — elecV2P 5.3 Medium2026-03-28

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3344 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.