Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CWE-36 (绝对路径遍历) — Vulnerability Class 103

103 vulnerabilities classified as CWE-36 (绝对路径遍历). AI Chinese analysis included.

CVE IDTitleCVSSSeverityPublished
CVE-2026-34515 AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows — aiohttp 5.3 -2026-04-01
CVE-2026-4373 JetFormBuilder <= 3.5.6.2 - Unauthenticated Arbitrary File Read via Media Field — JetFormBuilder — Dynamic Blocks Form Builder 7.5 High2026-03-21
CVE-2026-0846 Arbitrary File Read via Absolute Path Input in nltk.util.filestring() — nltk/nltk 7.5 -2026-03-09
CVE-2026-2753 Navtor NavBox 安全漏洞 — NavBox 7.5 High2026-03-06
CVE-2026-28414 Gradio has Absolute Path Traversal on Windows with Python 3.13+ — gradio 7.5 High2026-02-27
CVE-2026-26337 Hyland Alfresco Transformation Service Absolute Path Traversal Arbitrary File Read and SSRF — Alfresco Transformation Service (Enterprise) 8.2 High2026-02-19
CVE-2026-1330 HAMASTAR Technology|MeetingHub - Arbitrary File Read — MeetingHub 7.5 High2026-01-22
CVE-2026-1020 Gotac|Police Statistics Database System - Absolute Path Traversal — Police Statistics Database System 5.3 Medium2026-01-16
CVE-2026-1018 Gotac|Police Statistics Database System - Arbitrary File Read — Police Statistics Database System 7.5 High2026-01-16
CVE-2026-20834 Windows Spoofing Vulnerability — Windows 10 Version 1607 4.6 Medium2026-01-13
CVE-2025-15237 Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal — QOCA aim AI Medical Cloud Platform 4.3 Medium2026-01-05
CVE-2025-15236 Quanta Computer|QOCA aim AI Medical Cloud Platform - Path Traversal — QOCA aim AI Medical Cloud Platform 4.3 Medium2026-01-05
CVE-2025-15227 WELLTEND TECHNOLOGY| BPMFlowWebkit - Arbitrary File Read — BPMFlowWebkit 7.5 High2025-12-29
CVE-2025-14848 Advantech WebAccess/SCADA Absolute Path Traversal — WebAccess/SCADA 4.3 Medium2025-12-18
CVE-2025-67898 Mailjet MJML 安全漏洞 — MJML 4.5 Medium2025-12-14
CVE-2025-34392 Barracuda RMM < 2025.1.1 Service Center Absolute Path Traversal RCE — RMM 9.8AICriticalAI2025-12-10
CVE-2025-14253 Galaxy Software Services|Vitals ESP - Arbitrary File Read — Vitals ESP 4.9 Medium2025-12-08
CVE-2025-36357 IBM Planning Analytics Local Directory Traversal — IBM Planning Analytics Local 8.0 High2025-11-17
CVE-2025-7846 WordPress User Extra Fields <= 16.7 - Authenticated (Subscriber+) Arbitrary File Deletion via save_fields Function — WordPress User Extra Fields 8.8 High2025-10-31
CVE-2025-8575 LWS Cleaner <= 2.4.1.3 - Authenticated (Administrator+) Arbitrary File Deletion via 'lws_cl_delete_file' — LWS Cleaner 7.2 High2025-09-12
CVE-2025-9518 atec Debug <= 1.2.22 - Authenticated (Administrator+) Arbitrary File Deletion — atec Debug 7.2 High2025-09-04
CVE-2025-9516 atec Debug <= 1.2.22 - Authenticated (Administrator+) Arbitrary File Read — atec Debug 4.9 Medium2025-09-04
CVE-2025-9259 Uniong|WebITR - Arbitrary File Reading through Path Traversal — WebITR 6.5 Medium2025-08-22
CVE-2025-9258 Uniong|WebITR - Arbitrary File Reading through Path Traversal — WebITR 6.5 Medium2025-08-22
CVE-2025-9257 Uniong|WebITR - Arbitrary File Reading through Path Traversal — WebITR 6.5 Medium2025-08-22
CVE-2025-9256 Uniong|WebITR - Arbitrary File Reading through Path Traversal — WebITR 6.5 Medium2025-08-22
CVE-2025-57790 Path Traversal Vulnerability — CommCell 9.8 -2025-08-20
CVE-2025-8912 WellChoose|Organization Portal System - Arbitrary File Reading through Path Traversal — Organization Portal System 7.5 High2025-08-13
CVE-2025-8909 WellChoose|Organization Portal System - Arbitrary File Reading through Path Traversal — Organization Portal System 6.5 Medium2025-08-13
CVE-2025-8213 NinjaScanner – Virus & Malware scan <= 3.2.5 - Authenticated (Administrator+) Arbitrary File Deletion — NinjaScanner – Virus & Malware scan 7.2 High2025-07-31

Vulnerabilities classified as CWE-36 (绝对路径遍历) represent 103 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.