Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-22 (对路径名的限制不恰当(路径遍历)) — Vulnerability Class 3352

3352 vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2021-36286 Dell SupportAssist Client 后置链接漏洞 — SupportAssist Client Consumer 7.1 High2021-09-28
CVE-2021-24638 OMGF < 4.5.4 - Unauthenticated Path Traversal in REST API — OMGF | Host Google Fonts Locally 9.1 -2021-09-20
CVE-2021-3806 Path Traversal in Pardus Software Center — Pardus Software Center 5.3 Medium2021-09-18
CVE-2021-39208 WriteEntryToDirectory used for an archive extraction is vulnerable to partial path traversal. — sharpcompress 4.3 Medium2021-09-16
CVE-2021-23043 F5 BIG-IP 路径遍历漏洞 — BIG-IP 6.5 -2021-09-14
CVE-2021-37532 SAP Business One 路径遍历漏洞 — SAP Business One 4.3 -2021-09-14
CVE-2021-40357 Siemens Teamcenter Active Workspace 路径遍历漏洞 — Teamcenter Active Workspace V4.3 7.2 -2021-09-14
CVE-2021-37200 Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS 7.7 -2021-09-14
CVE-2021-38360 wp-publications <= 0.0 Local File Include — wp-publications 8.3 High2021-09-10
CVE-2021-25452 Samsung SMR 输入验证错误漏洞 — Samsung Mobile Devices 5.5 Medium2021-09-09
CVE-2021-22704 多款 Schneider Electric 产品路径遍历漏洞 — Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) 9.1 -2021-09-02
CVE-2021-36031 Magento Commerce Path Traversal In `theme[preview_image]` Parameter Could Lead To Remote Code Execution — Magento Commerce 7.2 High2021-09-01
CVE-2021-39180 Path Traversal in Archive Handling Leading to Code Execution — OpenOLAT 8.1 High2021-08-31
CVE-2021-37713 Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization — node-tar 8.2 High2021-08-31
CVE-2021-39316 ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure — ZoomSounds - WordPress Wave Audio Player with Playlist 7.5 High2021-08-31
CVE-2021-33555 A vulnerability may allow remote attackers to read arbitrary files on the server of the WirelessHART-Gateway — WHA-GW-F2D2-0-AS- Z2-ETH 7.5 High2021-08-31
CVE-2021-37701 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links — node-tar 8.2 High2021-08-31
CVE-2021-37712 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links — node-tar 8.2 High2021-08-31
CVE-2021-24549 AceIDE <= 2.6.2 - Authenticated (admin+) Arbitrary File Access — AceIDE 4.9 -2021-08-23
CVE-2021-22933 Pulse Secure Pulse Connect Secure 路径遍历漏洞 — Pulse Connect Secure 6.5 -2021-08-16
CVE-2021-24363 Photo Gallery < 1.5.75 - File Upload Path Traversal — Photo Gallery by 10Web – Mobile-Friendly Image Gallery 4.9 -2021-08-16
CVE-2021-21501 ServiceComb ServiceCenter Directory Traversal — Apache ServiceComb 9.1 -2021-08-10
CVE-2021-34638 WordPress Download Manager <= 3.1.24 Authenticated Directory Traversal — WordPress Download Manager 6.5 Medium2021-08-05
CVE-2021-32804 Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization — node-tar 8.2 High2021-08-03
CVE-2021-32803 Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning — node-tar 8.2 High2021-08-03
CVE-2021-32814 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Skytable — skytable 8.8 High2021-08-03
CVE-2020-5370 DELL EMC OpenManage Enterprise 路径遍历漏洞 — OpenManage Enterprise 7.9 High2021-07-22
CVE-2021-35968 Learningdigital.com, Inc. Orca HCM - Path Traversal-2 — Orca HCM 4.3 Medium2021-07-19
CVE-2021-35967 Learningdigital.com, Inc. Orca HCM - Path Traversal-1 — Orca HCM 5.3 Medium2021-07-19
CVE-2021-24453 Include Me <= 1.2.1 - Authenticated Remote Code Execution (RCE) via LFI log poisoning — Include Me 8.8 -2021-07-19

Vulnerabilities classified as CWE-22 (对路径名的限制不恰当(路径遍历)) represent 3352 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.