Weaknesses of type CWE-22

5,906 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-41203CRITICALci4ms Theme::upload is vulnerable to Zip Slip leading to RCEEPSS 0.7%CVE-2025-26534HIGHWordPress Helloprint Plugin <= 2.0.7 - Arbitrary File Deletion vulnerabilityEPSS 0.7%CVE-2026-33513HIGHAVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)EPSS 0.7%CVE-2022-43518MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise web interface. Successful exploitation of this vulnEPSS 0.7%CVE-2026-33195HIGHRails Active Storage has possible Path Traversal in DiskServiceEPSS 0.7%CVE-2025-55282CRITICALaiven-db-migrate allows Privilege Escalation via unrestricted search_path during migrationEPSS 0.7%CVE-2022-44532MEDIUMAn authenticated path traversal vulnerability exists in the Aruba EdgeConnect Enterprise command line interface. Successful exploitation of EPSS 0.7%CVE-2023-2273MEDIUMRapid7 Insight Agent Directory TraversalEPSS 0.7%CVE-2024-32982HIGHLitestar and Starlite affected by Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.7%CVE-2024-56514MEDIUMKarmada Tar Slips in CRDs archive extractionEPSS 0.7%CVE-2024-23340MEDIUM@hono/node-server can't handle "double dots" in URLEPSS 0.7%CVE-2023-6562HIGHJPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if thEPSS 0.7%CVE-2025-23562HIGHWordPress XLSXviewer plugin <= 2.1.1 - Arbitrary File Deletion vulnerabilityEPSS 0.7%CVE-2025-32950MEDIUMio.jmix.localfs:jmix-localfs has a Path Traversal in Local File StorageEPSS 0.7%CVE-2026-47897HIGHApache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator clientEPSS 0.7%CVE-2021-27771HIGHHCL Sametime is susceptible a file transfer service vulnerabilityEPSS 0.7%CVE-2026-23593HIGHUnauthenticated Limited File Read allows Data Exposure in Web InterfaceEPSS 0.7%CVE-2026-40912HIGHTraefik: StripPrefixRegex auth bypass via Path/RawPath desyncEPSS 0.7%CVE-2023-47803MEDIUMA vulnerability regarding improper limitation of a pathname to a restricted directory ('Path Traversal') is found in the Language Settings fEPSS 0.7%CVE-2024-24307HIGHPath Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remoEPSS 0.7%