Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3364

3364 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-3675 Insufficient input validation when downloading certain file types. — GateManager 6.5 Medium2024-04-18
CVE-2024-28073 SolarWinds Serv-U Directory Traversal Remote Code Execution Vulnerability — ServU 8.4 High2024-04-17
CVE-2024-1132 Keycloak: path transversal in redirection validation 8.1 High2024-04-17
CVE-2024-32024 Kohya_ss vulenrable to path injection in `common_gui.py` `add_pre_postfix` function (`GHSL-2024-023`) — kohya_ss 6.5 Medium2024-04-16
CVE-2024-32023 Kohya_ss vulnerable to path injection in `common_gui.py` `find_and_replace` function (`GHSL-2024-024`) — kohya_ss 6.5 Medium2024-04-16
CVE-2024-31451 Limited file write in routes.py (GHSL-2023-250) — DocsGPT 5.3 Medium2024-04-16
CVE-2024-1961 Path Traversal leading to Arbitrary File Write and RCE in vertaai/modeldb — vertaai/modeldb 9.8 -2024-04-16
CVE-2024-1558 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 6.5 -2024-04-16
CVE-2024-1594 Local File Read via Path Traversal in mlflow/mlflow — mlflow/mlflow 7.5 -2024-04-16
CVE-2024-3571 Path Traversal in langchain-ai/langchain — langchain-ai/langchain 9.8 -2024-04-16
CVE-2024-1483 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 7.5 -2024-04-16
CVE-2024-1560 Path Traversal Vulnerability in mlflow/mlflow — mlflow/mlflow 7.5 -2024-04-16
CVE-2024-1593 Path Traversal via Parameter Smuggling in mlflow/mlflow — mlflow/mlflow 9.1 -2024-04-16
CVE-2023-38511 iTop Dashboard editor vulnerable dashboard config file parameter — iTop 5.0 Medium2024-04-15
CVE-2024-3783 Path Traversal vulnerability in WBSAirback — White Bear Solutions 7.7 High2024-04-15
CVE-2023-52144 WordPress Product Feed Manager plugin <= 7.3.15 - Directory Traversal vulnerability — Product Feed Manager 5.5 Medium2024-04-15
CVE-2024-3737 cym1102 nginxWebUI addOver findCountByQuery path traversal — nginxWebUI 6.3 Medium2024-04-13
CVE-2024-31462 Limited file write in Stable-diffusion-webui - GHSL-2024-010 — stable-diffusion-webui 6.3 Medium2024-04-12
CVE-2024-1511 Path Traversal Vulnerability in parisneo/lollms-webui — parisneo/lollms-webui 8.8AIHighAI2024-04-10
CVE-2024-1728 Local File Inclusion in gradio-app/gradio — gradio-app/gradio 9.8AICriticalAI2024-04-10
CVE-2024-31287 WordPress Media Library Folders plugin <= 8.1.8 - Directory Traversal vulnerability — Media Library Folders 6.5 Medium2024-04-10
CVE-2024-31240 WordPress WP Poll Maker plugin <= 3.1 - Auth. Arbitrary File Deletion vulnerability — WP Poll Maker 7.7 High2024-04-10
CVE-2024-1790 Ajax Load More <= 7.0.1 - Authenticated (Admin+) Directory Traversal to Arbitrary File Read — Ajax Load More – Infinite Scroll, Load More, & Lazy Load 4.9 Medium2024-04-09
CVE-2024-1974 HT Mega – Absolute Addons For Elementor <= 2.4.5 - Authenticated (Contributor+) Directory Traversal — HT Mega Addons for Elementor – Elementor Widgets & Template Builder 8.8 High2024-04-09
CVE-2024-31457 gin-vue-admin background arbitrary code coverage vulnerability — gin-vue-admin 7.7 High2024-04-09
CVE-2024-31487 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox 5.8 Medium2024-04-09
CVE-2023-47541 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox 6.5 Medium2024-04-09
CVE-2024-23671 Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox 7.9 High2024-04-09
CVE-2024-2224 Privilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466) — GravityZone Control Center (On Premises) 8.1 High2024-04-09
CVE-2024-31860 Apache Zeppelin: Path traversal vulnerability — Apache Zeppelin 6.5AIMediumAI2024-04-09

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3364 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.