Fallos del tipo CWE-22

5890 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-73765HIGHAuthenticated Path Traversal Vulnerabilities Lead to Remote Code Execution in AOS-CXEPSS 0.9%CVE-2026-84086HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.9%CVE-2026-8023HIGHPath traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file readEPSS 0.9%CVE-2025-11913MEDIUMShenzhen Ruiming Technology Streamax Crocus Service.do download path traversalEPSS 0.9%CVE-2026-63454HIGHAuthenticated Path Traversal Vulnerability Leads to Remote Code Execution in AOS-CXEPSS 0.9%CVE-2026-35174CRITICALChyrp Lite has a Path Traversal to Remote Code ExecutionEPSS 0.9%CVE-2026-49506HIGHDell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path TraEPSS 0.9%CVE-2024-25164HIGHiA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download fuEPSS 0.9%CVE-2025-28072HIGHPHPGurukul Pre-School Enrollment System is vulnerable to Directory Traversal in manage-teachers.php.EPSS 0.9%CVE-2023-42487HIGHSoundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 0.9%CVE-2022-44942HIGHCasdoor before v1.126.1 was discovered to contain an arbitrary file deletion vulnerability via the uploadFile function.EPSS 0.9%CVE-2026-69807HIGHPowerShell Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2020-36628MEDIUMCalsign APDE ZIP File CopyBuildTask.java handleExtract path traversalEPSS 0.9%CVE-2022-4748MEDIUMFlatPress File Delete panel.mediamanager.file.php doItemActions path traversalEPSS 0.9%CVE-2025-2742MEDIUMzhijiantianya ruoyi-vue-pro Material Upload Interface upload-permanent path traversalEPSS 0.9%CVE-2021-20030HIGHSonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containingEPSS 0.9%CVE-2026-18027MEDIUMWebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels <= 4.9.8 - Authenticated (Subscriber+) Arbitrary File Read via 'customer_note' ParameterEPSS 0.9%CVE-2025-32509HIGHWordPress Simple WP Events plugin <= 1.8.17 - Arbitrary File Deletion vulnerabilityEPSS 0.9%CVE-2024-46212MEDIUMAn issue in the component /index.php?page=backup/export of REDAXO CMS v5.17.1 allows attackers to execute a directory traversal.EPSS 0.9%CVE-2024-5456HIGHPanda Video <= 1.4.0 - Authenticated (Contributor+) Local File InclusionEPSS 0.9%