Weaknesses of type CWE-22

5,868 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-84889HIGHA path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystemEPSS 0.9%CVE-2021-33722—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability EPSS 0.9%CVE-2024-8875MEDIUMvedees wcms finder.php path traversalEPSS 0.9%CVE-2025-22923HIGHAn issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST reqEPSS 0.9%CVE-2024-23721HIGHA Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calEPSS 0.9%CVE-2025-15031HIGHPath Traversal Vulnerability in mlflow/mlflowEPSS 0.9%CVE-2025-34058HIGHHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadEPSS 0.9%CVE-2025-29847HIGHApache Linkis: Arbitrary File Read via Double URL Encoding BypassEPSS 0.9%CVE-2026-25475MEDIUMOpenClaw Vulnerable to Local File Inclusion via MEDIA: Path ExtractionEPSS 0.9%CVE-2023-27577MEDIUMPath Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files in flarumEPSS 0.9%CVE-2025-56431HIGHDirectory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via thEPSS 0.9%CVE-2025-56430HIGHDirectory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via thEPSS 0.9%CVE-2026-37531CRITICALAGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367EPSS 0.9%CVE-2026-67200HIGHPerspective 5.0.0 Path Traversal via cwd_static_file_handlerEPSS 0.9%CVE-2026-26064CRITICALcalibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code ExecutionEPSS 0.9%CVE-2022-4583MEDIUMjLEMS JUtil.java unpackJar path traversalEPSS 0.9%CVE-2024-32117MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.EPSS 0.9%CVE-2024-28335CRITICALLektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates dEPSS 0.8%CVE-2023-27475HIGHGoutil vulnerable to path traversal when unzipping filesEPSS 0.8%CVE-2024-32386HIGHDirectory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain senEPSS 0.8%