Weaknesses of type CWE-22

5,880 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-2623MEDIUMBlossom File Upload BLOSManager.java put path traversalEPSS 0.8%CVE-2022-34365MEDIUMWMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorizeEPSS 0.8%CVE-2025-66429HIGHAn issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of aEPSS 0.8%CVE-2023-23136MEDIUMlmxcms v1.41 was discovered to contain an arbitrary file deletion vulnerability via BackdbAction.class.php.EPSS 0.8%CVE-2024-34523HIGHAChecker 1.5 allows remote attackers to read the contents of arbitrary files via the download.php path parameter by using Unauthenticated PaEPSS 0.8%CVE-2023-6160LOWLifterLMS <= 7.4.2 - Authenticated(Administrator+) Directory Traversal to Arbitrary CSV File DeletionEPSS 0.8%CVE-2024-11992CRITICALPath traversal vulnerability in Quick.CMSEPSS 0.8%CVE-2022-41212MEDIUMDue to insufficient input validation, SAP NetWeaver Application Server ABAP and ABAP Platform allows an attacker with high level privileges EPSS 0.8%CVE-2025-60722MEDIUMMicrosoft OneDrive for Android Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-8442HIGHWP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' ParameterEPSS 0.8%CVE-2026-39399CRITICALNuGet Gallery: Arbitrary Blob Overwrite via Nuspec Confusion and URI Fragment TruncationEPSS 0.8%CVE-2022-23470HIGHArbitrary file access in the Galaxy data analysis platformEPSS 0.8%CVE-2024-57170MEDIUMSOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticatEPSS 0.8%CVE-2024-46644MEDIUMeNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via edit_file.EPSS 0.8%CVE-2024-13984CRITICALQi'anxin TianQing Management Center rptsvr Arbitrary File UploadEPSS 0.8%CVE-2026-47612HIGHNVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathnamEPSS 0.8%CVE-2026-92970HIGHHUBzero CMS through 2.2.32 Path Traversal via File UploadEPSS 0.8%CVE-2025-2158HIGHWordPress Review Plugin: The Ultimate Solution for Building a Review Website <= 5.3.5 - Authenticated (Contributor+) Local File Inclusion via Post Custom FieldsEPSS 0.8%CVE-2025-65287HIGHAn unauthenticated directory traversal vulnerability in cgi-bin/upload.cgi in SNMP Web Pro 1.1 allows a remote attacker to read arbitrary fiEPSS 0.8%CVE-2026-40982CRITICALSpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious EPSS 0.8%