Weaknesses of type CWE-22

5,902 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-6321HIGHfast-uri vulnerable to path traversal via percent-encoded dot segmentsEPSS 0.8%CVE-2026-30278CRITICALAn arbitrary file overwrite vulnerability in FLY is FUN Aviation Navigation v35.33 allows attackers to overwrite critical internal files viaEPSS 0.8%CVE-2024-27575HIGHINOTEC Sicherheitstechnik WebServer CPS220/64 3.3.19 allows a remote attacker to read arbitrary files via absolute path traversal, such as wEPSS 0.8%CVE-2026-40491MEDIUMgdown Affected by Arbitrary File Write via Path Traversal in gdown.extractallEPSS 0.8%CVE-2025-26615CRITICALPath Traversal endpoint 'examples.php' parameter 'src' in WeGIAEPSS 0.8%CVE-2025-6465MEDIUMPath traversal in image upload with preview overwriteEPSS 0.8%CVE-2025-1543MEDIUMiteachyou Dreamer CMS ueditor-1.4.3.3 path traversalEPSS 0.8%CVE-2024-53523HIGHJSFinder commit d70ab9bc5221e016c08cffaf0d9ac79646c90645 is vulnerable to Directory Traversal in the find_by_file function.EPSS 0.8%CVE-2023-6190CRITICALAuthenicated Path Traversal in İzmir Katip Çelebi UniversityEPSS 0.8%CVE-2026-95701MEDIUMMISP Path Traversal via Organization Name in Org-Statistics Logo CheckEPSS 0.8%CVE-2025-0818MEDIUMMultiple elFinder Plugins <= (Various Versions) - Directory Traversal to Arbitrary File DeletionEPSS 0.8%CVE-2026-75482HIGHSWE-agent Trajectory Inspector Path Traversal File DisclosureEPSS 0.8%CVE-2026-1311HIGHWorry Proof Backup <= 0.2.4 - Authenticated (Subscriber+) Path Traversal via Backup UploadEPSS 0.8%CVE-2023-28833LOWUnrestricted filenames for logo or favicon as admin in the theming settings in nextcloud serverEPSS 0.8%CVE-2026-75594HIGHKirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handlingEPSS 0.8%CVE-2025-70796HIGHAn unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 20EPSS 0.8%CVE-2025-10236MEDIUMbinary-husky gpt_academic LaTeX File latex_toolbox.py merge_tex_files_ path traversalEPSS 0.8%CVE-2023-25804HIGHRoxy-WI vulnerable to Limited Path Traversal in name parameterEPSS 0.8%CVE-2023-45382HIGHIn the module "SoNice Retour" (sonice_retour) up to version 2.1.0 from Common-Services for PrestaShop, a guest can download personal informaEPSS 0.8%CVE-2025-25295HIGHLabel Studio has a Path Traversal Vulnerability via image FieldEPSS 0.8%