Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-23 (相对路径遍历) — Vulnerability Class 339

339 vulnerabilities classified as CWE-23 (相对路径遍历). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-55115 BMC Control-M/Agent path traversal local privilege escalation — Control-M/Agent 8.8 High2025-09-16
CVE-2025-10203 Relative Path Traversal Vulnerability in Digilent WaveForms — WaveForms 7.8 High2025-09-15
CVE-2025-58760 Tautulli vulnerable to Unauthenticated Path Traversal in `/image` endpoint — Tautulli 8.6 High2025-09-09
CVE-2025-53609 Fortinet FortiWeb 安全漏洞 — FortiWeb 4.7 Medium2025-09-09
CVE-2025-58752 Vite's `server.fs` settings were not applied to HTML files — vite 4.7AIMediumAI2025-09-08
CVE-2025-25048 IBM Jazz Foundation path traversal — Jazz Foundation 6.5 Medium2025-09-04
CVE-2025-55748 XWiki Platform's configuration files can be accessed through jsx and sx endpoints — xwiki-platform 7.5AIHighAI2025-09-03
CVE-2025-55747 XWiki Platform's configuration files can be accessed through the webjars API — xwiki-platform 7.5AIHighAI2025-09-03
CVE-2025-9570 Sunnet|eHRD CTMS - Arbitrary File Reading through Path Traversal — eHRD CTMS 4.9 Medium2025-09-01
CVE-2025-55202 Opencast has a partial path traversal vulnerability in UI config — opencast 6.5 -2025-08-29
CVE-2025-9639 Ai3|QbiCRMGateway - Arbitrary File Reading through Path Traversal — QbiCRMGateway 7.5 High2025-08-29
CVE-2021-4459 SMA: Directory Traversal in Sunny Boy <3.10.27.R — Boy 3.0 6.5 Medium2025-08-27
CVE-2025-8464 Drag and Drop Multiple File Upload for Contact Form 7 <= 1.3.9.0 - Directory Traversal via `wpcf7_guest_user_id` Cookie — Drag and Drop Multiple File Upload for Contact Form 7 5.3 Medium2025-08-16
CVE-2024-48892 Fortinet FortiSOAR 安全漏洞 — FortiSOAR 6.4 Medium2025-08-12
CVE-2024-40588 Fortinet多款产品 安全漏洞 — FortiCamera 4.2 Medium2025-08-12
CVE-2025-53779 Windows Kerberos Elevation of Privilege Vulnerability — Windows Server 2025 7.2 High2025-08-12
CVE-2025-55013 Assemblyline 4 Service Client: Arbitrary Write through path traversal in Client code — assemblyline 4.2 Medium2025-08-09
CVE-2025-53082 SAMSUNG DMS 安全漏洞 — Data Management Server 6.1 Medium2025-07-29
CVE-2025-54531 JetBrains TeamCity 安全漏洞 — TeamCity 7.7 High2025-07-28
CVE-2025-54317 Logpoint 安全漏洞 — Logpoint 8.4 High2025-07-20
CVE-2025-7619 WellChoose|BatchSignCS - Arbitrary File Write through Path Traversal — BatchSignCS 8.8 High2025-07-14
CVE-2025-48817 Remote Desktop Client Remote Code Execution Vulnerability — Remote Desktop client for Windows Desktop 8.8 High2025-07-08
CVE-2025-7146 Jhenggao iPublish System - Arbitrary File Reading through Path Traversal — iPublish System 7.5 High2025-07-08
CVE-2025-52207 MIKO MikoPBX 安全漏洞 — MikoPBX 9.9 Critical2025-06-27
CVE-2025-52922 InnoShop 安全漏洞 — InnoShop 7.4 High2025-06-23
CVE-2025-34510 Sitecore XM, XC, and XP Post-Auth RCE via Zip Slip — Experience Manager 8.8 High2025-06-17
CVE-2025-33112 IBM AIX command execution — AIX 8.4 High2025-06-10
CVE-2025-3365 Relative Path Traversal in OnlineSuite — OnlineSuite 9.8 Critical2025-06-06
CVE-2025-49466 aerc 安全漏洞 — aerc 5.8 Medium2025-06-05
CVE-2025-48957 AstrBot Has Path Traversal Vulnerability in /api/chat/get_file — AstrBot 7.5 High2025-06-02

Vulnerabilities classified as CWE-23 (相对路径遍历) represent 339 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.