Fallos del tipo CWE-22

5946 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-72850CRITICALBudibase before 3.40.0 Arbitrary File Write via Path TraversalEPSS 0.6%CVE-2023-44395MEDIUMAutolab has Path Traversal vulnerability in Assessment functionalityEPSS 0.6%CVE-2026-59555CRITICALWordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-35743HIGHWordPress SC filechecker plugin <= 0.6 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-35744HIGHWordPress Upunzipper plugin <= 1.0.0 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2024-55658HIGHSiYuan has an arbitrary file read and path traversal via /api/export/exportResourcesEPSS 0.6%CVE-2026-47884CRITICALSpring Framework Improper Path Limitation in XsltViewEPSS 0.6%CVE-2026-42520HIGHJenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing aEPSS 0.6%CVE-2024-37419HIGHWordPress Cowidgets – Elementor Addons plugin <= 1.1.1 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2024-43955CRITICALWordPress Droip plugin <= 1.1.1 - Unauthenticated Arbitrary File Download/Deletion vulnerabilityEPSS 0.6%CVE-2024-8941HIGHPath Traversal vulnerability on ScriptcaseEPSS 0.6%CVE-2026-33656CRITICALEspoCRM vulnerable to authenticated RCE via Formula with path traversal in attachment `sourceId`, exploitable by admin userEPSS 0.6%CVE-2025-25371HIGHNASA cFS (Core Flight System) Aquila is vulnerable to path traversal in the OSAL module, allowing the override of any arbitrary file on the EPSS 0.6%CVE-2026-74044HIGHWazuh 4.0.0 < 4.14.6 Path Traversal Arbitrary Directory Deletion via Cluster HelloEPSS 0.6%CVE-2025-5993CRITICALPath Traversal in ITCube CRMEPSS 0.6%CVE-2024-8262CRITICALPath Traversal in Proliz Software's OBSEPSS 0.6%CVE-2026-6282HIGHA potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remoteEPSS 0.6%CVE-2026-40547MEDIUMPath Traversal in SOPlanningEPSS 0.6%CVE-2024-45593CRITICALNix affected by unsafe NAR unpackingEPSS 0.6%CVE-2025-9435MEDIUMPath TraversalEPSS 0.6%