Weaknesses of type CWE-22

5,925 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-17173MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.7%CVE-2026-68062MEDIUMSKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can logEPSS 0.7%CVE-2025-41428MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitraEPSS 0.7%CVE-2025-12638HIGHPath Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file()EPSS 0.7%CVE-2026-9195CRITICALCross-site scripting in Progress MarkLogic Server Query ConsoleEPSS 0.7%CVE-2024-48224HIGHFunadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.EPSS 0.7%CVE-2024-10585MEDIUMInfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File ReadingEPSS 0.7%CVE-2025-65077HIGHRelative path traversal vulnerability in Embedded Solutions FrameworkEPSS 0.7%CVE-2025-22152CRITICALImproper Path Validation Enables Path Traversal in Multiple Components in AtheosEPSS 0.7%CVE-2025-69770CRITICALA zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commandEPSS 0.7%CVE-2021-47977HIGHWordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory TraversalEPSS 0.7%CVE-2024-32023MEDIUMKohya_ss vulnerable to path injection in `common_gui.py` `find_and_replace` function (`GHSL-2024-024`)EPSS 0.7%CVE-2026-25525MEDIUMOpenMage LTS has Path Traversal Filter Bypass in Dataflow ModuleEPSS 0.7%CVE-2026-45727HIGHCloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletionEPSS 0.7%CVE-2026-63312HIGHNLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File ReadEPSS 0.7%CVE-2025-66687HIGHDoom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game filesEPSS 0.7%CVE-2026-41058HIGHAVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideoEPSS 0.7%CVE-2026-35214HIGHBudibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writeEPSS 0.7%CVE-2026-88937HIGHknowns through 0.33.0 Path Traversal via Template EngineEPSS 0.7%CVE-2026-62384HIGHNLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2EPSS 0.7%