Weaknesses of type CWE-22

5,866 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-34790HIGHEndian Firewall /cgi-bin/backup.cgi remove ARCHIVE Directory TraversalEPSS 0.9%CVE-2025-10488HIGHDirectorist: AI-Powered Business Directory Plugin with Classified Ads Listings <= 8.4.8 - Authenticated (Subscriber+) Arbitrary File MoveEPSS 0.9%CVE-2024-39399HIGH[Paris] Path Traversal lead to local file readEPSS 0.9%CVE-2026-16078MEDIUMWCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' ParameterEPSS 0.9%CVE-2024-2294MEDIUMBackuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory TraversalEPSS 0.9%CVE-2026-32140CRITICALDataease: Redshift JDBC RCE BypassEPSS 0.9%CVE-2023-34238MEDIUM Local File Inclusion vulnerability in GatsbyEPSS 0.9%CVE-2021-42022—A vulnerability has been identified in SIMATIC eaSie PCS 7 Skill Package (All versions < V21.00 SP3). When downloading files, the affected sEPSS 0.9%CVE-2026-85199HIGHEclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiersEPSS 0.9%CVE-2024-8769CRITICALArbitrary File Deletion via Relative Path Traversal in aimhubio/aimEPSS 0.9%CVE-2025-29420HIGHPerfreeBlog v4.0.11 has a directory traversal vulnerability in the getThemeFilesByName function.EPSS 0.9%CVE-2023-28382HIGHDirectory traversal vulnerability in ESS REC Agent Server Edition series allows an authenticated attacker to view or alter an arbitrary fileEPSS 0.9%CVE-2023-1191MEDIUMfastcms ZIP File TemplateController.java path traversalEPSS 0.9%CVE-2026-58015MEDIUMGlib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receiveEPSS 0.9%CVE-2024-27946MEDIUMA vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). Downloading files overwrites files with the same name in thEPSS 0.9%CVE-2025-54926HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code exeEPSS 0.9%CVE-2023-28344HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application allows unauthenticated attackers EPSS 0.9%CVE-2023-32676MEDIUMAutolab tar slip in Install Assessment functionality (`GHSL-2023-081`)EPSS 0.9%CVE-2026-34607HIGHEmlog: Path Traversal in emUnZip() allows arbitrary file write leading to RCEEPSS 0.9%CVE-2024-44825HIGHDirectory Traversal vulnerability in Centro de Tecnologia da Informaco Renato Archer InVesalius3 v3.1.99995 allows attackers to write arbitrEPSS 0.9%