Weaknesses of type CWE-22

5,906 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2025-12000MEDIUMWPFunnels <= 3.6.2 - Authenticated (Administrator+) Arbitrary File Deletion via Path TraversalEPSS 0.7%CVE-2026-76652MEDIUMAuthenticated Directory Traversal Vulnerability in File Upload Functionality in TP-Link TL-MR6400 and Archer MR600EPSS 0.7%CVE-2026-11974HIGHMedia folder Addon < 4.1.7 - Unauthenticated Arbitrary File DownloadEPSS 0.7%CVE-2024-2224HIGHPrivilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-11466)EPSS 0.7%CVE-2026-3087MEDIUMshutil.unpack_archive() doesn't check for Windows absolute paths in ZIPsEPSS 0.7%CVE-2025-64075CRITICALA path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to EPSS 0.7%CVE-2025-2744MEDIUMzhijiantianya ruoyi-vue-pro Material Upload Interface upload-news-image path traversalEPSS 0.7%CVE-2025-6776MEDIUMxiaoyunjie openvpn-cms-flask File Upload controller.py upload path traversalEPSS 0.7%CVE-2025-67653MEDIUMAdvantech WebAccess/SCADA Path TraversalEPSS 0.7%CVE-2023-49793MEDIUMPath traversal in `CodeChecker server` in the endpoint of `CodeChecker store`EPSS 0.7%CVE-2025-8729MEDIUMMigoXLab LMeterX upload_service.py process_cert_files path traversalEPSS 0.7%CVE-2025-15449MEDIUMcld378632668 JavaMall MinioController.java delete path traversalEPSS 0.7%CVE-2025-47176HIGHMicrosoft Outlook Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-24689MEDIUMAn issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via mEPSS 0.7%CVE-2025-10176HIGHThe Hack Repair Guy's Plugin Archiver <= 2.0.4 - Authenticated (Administrator+) Arbitrary File DeletionEPSS 0.7%CVE-2022-38731MEDIUMQaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbiEPSS 0.7%CVE-2025-59352MEDIUMDragonfly allows arbitrary file read and write on a peer machineEPSS 0.7%CVE-2025-61557HIGHnixseparatedebuginfod before v0.4.1 is vulnerable to Directory Traversal.EPSS 0.7%CVE-2023-22320HIGHOpenAM Web Policy Agent (OpenAM Consortium Edition) provided by OpenAM Consortium parses URLs improperly, leading to a path traversal vulnerEPSS 0.7%CVE-2024-25659HIGHIn Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux serveEPSS 0.7%