Fallos del tipo CWE-22

5927 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-54760CRITICALLangroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file callsEPSS 0.6%CVE-2024-28171HIGHDelta Electronics DIAEnergie Path traversalEPSS 0.6%CVE-2025-27395HIGHA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit tEPSS 0.6%CVE-2025-45238CRITICALfoxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.EPSS 0.6%CVE-2022-20677MEDIUMCisco IOx Application Hosting Environment VulnerabilitiesEPSS 0.6%CVE-2019-25256HIGHVideoFlow Digital Video Protection DVP 2.10 Authenticated Directory TraversalEPSS 0.6%CVE-2025-34154CRITICALUnForm Server Manager < 10.1.12 Unauthenticated Arbitrary File ReadEPSS 0.6%CVE-2025-55149MEDIUMPath Traversal Vulnerability in PDF Review Function (CWE-22)EPSS 0.6%CVE-2024-11398HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in OTP reset functionality in Synology Router MEPSS 0.6%CVE-2024-44030HIGHWordPress Checkout Mestres WP plugin <= 8.6 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-22905HIGHAuthentication Bypass via URI TraversalEPSS 0.6%CVE-2024-6085HIGHPath Traversal in parisneo/lollmsEPSS 0.6%CVE-2025-24891CRITICALDumb Drop has an arbitrary file overwrite and path traversal for root shellEPSS 0.6%CVE-2026-6968HIGHMultiple Path Traversal Variants in awslabs/toughEPSS 0.6%CVE-2024-23768HIGHDremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in thEPSS 0.6%CVE-2025-14111LOWRarlab RAR App com.rarlab.rar path traversalEPSS 0.6%CVE-2026-40576CRITICALImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in excel-mcp-serverEPSS 0.6%CVE-2024-32869MEDIUMHono vulnerable to Restricted Directory Traversal in serveStatic with denoEPSS 0.6%CVE-2025-6772MEDIUMeosphoros-ai db-gpt import import_flow path traversalEPSS 0.6%CVE-2023-3698HIGHA Command injection vulnerability was found on Printer service of ADMEPSS 0.6%