Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3364

3364 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2023-3533 Chamilo LMS Unauthenticated Remote Code Execution via Arbitrary File Write — Chamilo 9.8 Critical2023-11-28
CVE-2022-41951 OroPlatform vulnerable to path traversal during temporary file manipulations — platform 8.6 High2023-11-27
CVE-2023-42000 Arcserve UDP Agent Unauthenticated Path Traversal File Upload — Arcserve UDP 9.8 Critical2023-11-27
CVE-2023-5607 Trellix Application and Change Control 路径遍历漏洞 — Trellix Application and Change Control (TACC) 8.4 High2023-11-27
CVE-2023-4593 Path Traversal in BVRP Software SLmail — SLmail 6.5 Medium2023-11-23
CVE-2023-6265 DrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal — Vigor2960 6.5 Medium2023-11-22
CVE-2023-6160 LifterLMS <= 7.4.2 - Authenticated(Administrator+) Directory Traversal to Arbitrary CSV File Deletion — LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes 3.3 Low2023-11-22
CVE-2021-22151 Kibana path traversal issue — Kibana 3.1 Low2023-11-22
CVE-2023-48299 TorchServe ZipSlip — serve 5.3 Medium2023-11-21
CVE-2023-22273 ZDI-CAN-21307: Adobe RoboHelp Server OnPublishFile Directory Traversal Remote Code Execution Vulnerability — RoboHelp 7.2 High2023-11-17
CVE-2023-6015 MLflow Arbitrary File Upload — mlflow/mlflow 9.8 -2023-11-16
CVE-2023-5245 Using MLeap for loading a saved model (zip archive) can lead to path traversal/arbitrary file creation and possibly remote code execution. 7.5 High2023-11-15
CVE-2023-6032 Schneider Electric Galaxy VS和Schneider Electric Galaxy VL 安全漏洞 — Galaxy VS 5.3 Medium2023-11-15
CVE-2023-40055 SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-09
CVE-2023-40054 SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-09
CVE-2023-46253 Remote code execution in Squidex — squidex 9.1 Critical2023-11-07
CVE-2023-39299 Music Station — Music Station 7.5 High2023-11-03
CVE-2023-3961 Samba: smbd allows client access to unix domain sockets on the file system as root — Red Hat Enterprise Linux 8 9.1 Critical2023-11-03
CVE-2023-41356 WisdomGarden Tronclass ilearn - Path Traversal — Tronclass ilearn 6.5 Medium2023-11-03
CVE-2023-41344 NCSIST ManageEngine MDM - Path Traversal — MDM 7.5 High2023-11-03
CVE-2023-20220 Cisco Firepower Management Center 安全漏洞 — Cisco Firepower Management Center 7.2 High2023-11-01
CVE-2023-33227 Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-01
CVE-2023-33226 Directory Traversal Remote Code Execution Vulnerability — Network Configuration Manager 8.0 High2023-11-01
CVE-2023-2621 Hitachi Energy MACH System Software 路径遍历漏洞 — MACH System Software 6.5 Medium2023-11-01
CVE-2023-46237 FOG path traversal via unauthenticated endpoint — fogproject 5.8 Medium2023-10-31
CVE-2023-43648 baserCMS Directory Traversal vulnerability in Form submission data management Feature — basercms 4.9 Medium2023-10-30
CVE-2023-42804 BigBlueButton Path Traversal – Reading Certain File Extensions — bigbluebutton 3.1 Low2023-10-30
CVE-2005-10002 almosteffortless secure-files Plugin secure-files.php sf_downloads path traversal — secure-files Plugin 5.5 Medium2023-10-29
CVE-2023-30967 Gotham Orbital Simulator path traversal — com.palantir.meta:orbital-simulator 9.8 Critical2023-10-25
CVE-2023-42488 EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — v3.0.6433.1964 7.5 High2023-10-25

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3364 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.