Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-23 (相对路径遍历) — Vulnerability Class 339

339 vulnerabilities classified as CWE-23 (相对路径遍历). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-33733 EspoCRM has Admin TemplateManager path traversal that allows arbitrary file read write and delete — espocrm 7.2 High2026-04-22
CVE-2026-5966 TeamT5|ThreatSonar Anti-Ransomware - Arbitrary File Deletion — ThreatSonar Anti-Ransomware 8.1 High2026-04-20
CVE-2026-31927 Anviz CX7 Firmware Relative Path Traversal — Anviz CX7 Firmware 4.9 Medium2026-04-17
CVE-2026-33435 Weblate: Remote code execution during backup restoration — weblate 8.1 High2026-04-15
CVE-2026-20081 Cisco Unity Connection Arbitrary File Download Vulnerability — Cisco Unity Connection 6.5 Medium2026-04-15
CVE-2026-20078 Cisco Unity Connection Arbitrary File Download Vulnerability — Cisco Unity Connection 6.5 Medium2026-04-15
CVE-2026-39814 Fortinet FortiWeb 安全漏洞 — FortiWeb 6.2 Medium2026-04-14
CVE-2026-27489 ONNX: Path Traversal via Symlink — onnx 5.5AIMediumAI2026-04-01
CVE-2026-32725 SciTokens C++: Relative Path Traversal Vulnerability — scitokens-cpp 8.3 High2026-03-31
CVE-2026-31831 Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint — Tautulli 7.5 -2026-03-30
CVE-2026-4415 GIGABYTE|Gigabyte Control Center - Arbitrary File Write — Gigabyte Control Center 8.1 High2026-03-30
CVE-2026-33206 calibre has a path traversal vulnerability — calibre 9.8 -2026-03-27
CVE-2026-33494 Ory Oathkeeper has a path traversal authorization bypass — oathkeeper 10.0 Critical2026-03-26
CVE-2026-29101 SuiteCRM Vulnerable to Directory Traversal to DoS in Modules — SuiteCRM 4.9 Medium2026-03-19
CVE-2026-29098 SuiteCRM has Relative Path Traversal via ModuleBuilder Modules ExportCustom Action — SuiteCRM 4.9 Medium2026-03-19
CVE-2026-29778 pyLoad: Arbitrary File Write via Path Traversal in edit_package() — pyload 7.1 High2026-03-07
CVE-2026-21659 Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion — Frick Controls Quantum HD 9.8 -2026-02-27
CVE-2025-62878 Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern — Rancher 9.9 Critical2026-02-25
CVE-2026-27202 GetSimple CMS: Uploaded Files (feature) Arbitrary File Read Vulnerability — GetSimpleCMS-CE 6.5AIMediumAI2026-02-20
CVE-2026-2818 Zip Slip Path Traversal in Snapshot Archive Extraction (Windows-Specific) — Spring Data Geode 8.2 High2026-02-20
CVE-2026-21620 TFTP Path Traversal — OTP 9.1AICriticalAI2026-02-20
CVE-2026-26362 Dell Unisphere for PowerMax 安全漏洞 — Unisphere for PowerMax 8.1 High2026-02-19
CVE-2025-58467 Qsync Central — Qsync Central 7.5AIHighAI2026-02-11
CVE-2026-1762 Enervista UR Setup Directory Traversal Vulnerability — Enervista 2.9 Low2026-02-10
CVE-2026-25057 Zip Slip in MarkUs config upload allowing RCE — Markus 9.1 Critical2026-02-09
CVE-2026-25575 NavigaTUM has a Path Traversal Vulnerability in the propose_edits functionality — NavigaTUM 7.5AIHighAI2026-02-04
CVE-2026-25121 apko is vulnerable to path traversal in apko dirFS which allows filesystem writes outside base — apko 7.5 High2026-02-04
CVE-2026-24909 vlt 安全漏洞 — vlt 5.9 Medium2026-01-27
CVE-2026-23890 pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin — pnpm 6.5 Medium2026-01-26
CVE-2026-1022 Gotac|Statistics Database System - Arbitrary File Read — Statistics Database System 7.5 High2026-01-16

Vulnerabilities classified as CWE-23 (相对路径遍历) represent 339 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.