Weaknesses of type CWE-22

5,880 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-40982CRITICALSpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious EPSS 0.8%CVE-2023-53979HIGHMyBB 1.8.32 Authenticated Remote Code Execution via Chained VulnerabilitiesEPSS 0.8%CVE-2024-34245MEDIUMAn arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in maEPSS 0.8%CVE-2024-46647MEDIUMeNMS 4.4.0 to 4.7.1 is vulnerable to Directory Traversal via upload_files.EPSS 0.8%CVE-2023-3348MEDIUMDirectory traversal vulnerability in Cloudflare WranglerEPSS 0.8%CVE-2025-7712CRITICALMadara - Core <= 2.2.3 - Unauthenticated Arbitrary File DeletionEPSS 0.8%CVE-2024-1165MEDIUMBrizy – Page Builder <= 2.4.39 - Authenticated (Contributor+) Directory TraversalEPSS 0.8%CVE-2026-40909HIGHWWBN AVideo has a Path Traversal in Locale Save Endpoint that Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)EPSS 0.8%CVE-2023-43044MEDIUMIBM License Metric Tool directory traversalEPSS 0.8%CVE-2025-67171HIGHIncorrect access control in the /templates/ component of RiteCMS v3.1.0 allows attackers to access sensitive files via directory traversal.EPSS 0.8%CVE-2023-45689—Arbitrary file read via path traversal in Titan MFT and Titan SFTP serversEPSS 0.8%CVE-2025-30895HIGHWordPress WpEvently Plugin <= 4.2.9 - PHP Object Injection vulnerabilityEPSS 0.8%CVE-2025-3055HIGHWP User Frontend Pro <= 4.1.3 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.8%CVE-2025-50349HIGHPHPGurukul Pre-School Enrollment System Project V1.0 is vulnerable to Directory Traversal in update-teacher-pic.php.EPSS 0.8%CVE-2023-7309CRITICALDahua Smart Park Integrated Management Platform Front-End Arbitrary File UploadEPSS 0.8%CVE-2026-3864MEDIUMCSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS serverEPSS 0.8%CVE-2023-25914HIGHAuthneticated Path Traversal in Danfoss AK-SM800AEPSS 0.8%CVE-2021-37532MEDIUMSAP Business One version - 10, due to improper input validation, allows an authenticated User to gain access to directory and view the conteEPSS 0.8%CVE-2025-64057HIGHDirectory traversal vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store files in arbitrarEPSS 0.8%CVE-2023-53907HIGHBludit 3.13.1 Authenticated Arbitrary File Download via Backup PluginEPSS 0.8%