Weaknesses of type CWE-22

6,014 results

Traversal de diretório (path traversal)

A aplicação recebe um caminho de arquivo fornecido pelo usuário e o usa para acessar arquivos sem validar adequadamente se o resultado fica dentro do diretório permitido. Um atacante injeta sequências como '../' ou '..' para "escapar" do diretório esperado e acessar arquivos sensíveis do sistema.

Example

Um site permite download de arquivos do diretório /uploads passando o nome via URL: download.php?file=documento.pdf. Um atacante envia file=../../etc/passwd e consegue ler arquivos fora de /uploads, porque o código não neutraliza a sequência '..'.

How to mitigate

Valide e canonicalize todo caminho fornecido pelo usuário antes de usá-lo: implemente uma whitelist de nomes permitidos, normalize caminhos para sua forma canônica, verifique se o resultado está dentro do diretório esperado, e use APIs de segurança da linguagem (ex: Path.normalize() + validação de prefix em Java, pathlib em Python).

CVE-2026-19438HIGHMint Workbench I Path traversal VulnerabilityEPSS 0.3%CVE-2026-17424MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-50559MEDIUMA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.3%CVE-2023-2270HIGHLocal privilege escalationEPSS 0.3%CVE-2024-23216MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS VenturaEPSS 0.3%CVE-2025-61646LOWWatchlist group mode reveals authors of edits with hidden authorshipEPSS 0.3%CVE-2025-43190MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26,EPSS 0.3%CVE-2025-61658LOWSpecial:GlobalContributions shows edits on wikis the viewer doesn't have access toEPSS 0.3%CVE-2025-10559HIGHPath Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2024-10933MEDIUMOpenBSD readdir directory traversalEPSS 0.3%CVE-2025-8941HIGHLinux-pam: incomplete fix for cve-2025-6020EPSS 0.3%CVE-2025-53905MEDIUMVim has path traversial issue with tar.vim and special crafted tar filesEPSS 0.3%CVE-2023-4782MEDIUMTerraform Allows Arbitrary File Write During Init OperationEPSS 0.3%CVE-2025-24329MEDIUMOAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management networkEPSS 0.3%CVE-2017-20181MEDIUMhgzojer Vocable Trainer VocableTrainerProvider.java path traversalEPSS 0.3%CVE-2025-69619MEDIUMA path traversal in My Text Editor v1.6.2 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.EPSS 0.3%CVE-2026-86136HIGHFireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant AEPSS 0.3%CVE-2026-10264MEDIUMlharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path traversalEPSS 0.3%CVE-2024-6281HIGHPath Traversal in parisneo/lollmsEPSS 0.3%CVE-2025-55214MEDIUMCopier safe template has filesystem write access outside destination pathEPSS 0.3%