Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-23 (相对路径遍历) — Vulnerability Class 339

339 vulnerabilities classified as CWE-23 (相对路径遍历). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2025-47445 WordPress Eventin plugin <= 4.0.26 - Arbitrary File Download Vulnerability — Eventin 7.5 High2025-05-14
CVE-2025-22859 Fortinet FortiClientEMS 安全漏洞 — FortiClientEMS 5.0 Medium2025-05-13
CVE-2025-24350 Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Device Admin 7.1 High2025-04-30
CVE-2025-24343 Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Solutions 5.4 Medium2025-04-30
CVE-2023-35816 DevExpress 安全漏洞 — DevExpress 3.5 Low2025-04-28
CVE-2025-46433 JetBrains TeamCity 安全漏洞 — TeamCity 4.9 Medium2025-04-25
CVE-2025-43016 JetBrains Rider 安全漏洞 — Rider 5.4 Medium2025-04-25
CVE-2025-27791 Collabora Online Vulnerable to Arbitrary File Write — online 6.8AIMediumAI2025-04-15
CVE-2025-32017 Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users — Umbraco-CMS 8.8 High2025-04-08
CVE-2025-32409 Ratta SuperNote A6 X2 Nomad 安全漏洞 — SuperNote A6 X2 Nomad 8.1 High2025-04-07
CVE-2025-32137 WordPress s2Member plugin <= 250419 - Local File Inclusion vulnerability — s2Member 4.9 Medium2025-04-04
CVE-2023-40714 Fortinet FortiSIEM 安全漏洞 — FortiSIEM 9.7 Critical2025-04-02
CVE-2025-2007 Import Export Suite for CSV and XML Datafeed <= 7.19 - Authenticated (Subscriber+) Arbitrary File Deletion — WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress 8.1 High2025-04-01
CVE-2025-29789 OpenEMR Has Directory Traversal in Load Code feature — openemr 6.5AIMediumAI2025-03-25
CVE-2025-27553 Apache Commons VFS: Possible path traversal issue when using NameScope.DESCENDENT — Apache Commons VFS--2025-03-23
CVE-2024-6583 Path Traversal in stangirard/quivr — stangirard/quivr 7.5 -2025-03-20
CVE-2024-8551 Path Traversal in modelscope/agentscope — modelscope/agentscope 9.8 -2025-03-20
CVE-2024-10513 Path Traversal in mintplex-labs/anything-llm — mintplex-labs/anything-llm 7.2 -2025-03-20
CVE-2024-7058 Relative Path Traversal in parisneo/lollms-webui — parisneo/lollms 6.5 -2025-03-20
CVE-2024-6483 Arbitrary File/Directory Deletion in aimhubio/aim — aimhubio/aim 9.1 -2025-03-20
CVE-2024-9363 Unauthorized File Deletion in polyaxon/polyaxon — polyaxon/polyaxon 7.5 -2025-03-20
CVE-2024-12019 Arbitrary File Read via Document API — LogicalDOC Community 6.5 -2025-03-14
CVE-2024-54449 Remote Code Execution (RCE) via Arbitrary File Write In Document API — LogicalDOC Community 8.8 -2025-03-14
CVE-2025-2056 WP Ghost <= 5.4.01 - Unauthenticated Limited File Read — WP Ghost (Hide My WP Ghost) – Security & Firewall 7.5 High2025-03-14
CVE-2025-23360 NVIDIA Nemo Framework 安全漏洞 — NeMo Framework 7.1 High2025-03-11
CVE-2025-26645 Remote Desktop Client Remote Code Execution Vulnerability — Remote Desktop client for Windows Desktop 8.8 High2025-03-11
CVE-2025-27610 Local File Inclusion in Rack::Static — rack 7.5 High2025-03-10
CVE-2025-23410 GMOD Apollo Relative Path Traversal — Apollo 9.8 Critical2025-03-04
CVE-2025-25130 WordPress Delete Comments By Status plugin <= 1.5.3 - Local File Inclusion vulnerability — Delete Comments By Status 7.5 High2025-03-03
CVE-2025-27410 PwnDoc Arbitrary File Write to RCE using Path Traversal in backup restore as admin — pwndoc 6.5 Medium2025-02-28

Vulnerabilities classified as CWE-23 (相对路径遍历) represent 339 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.