Fallos del tipo CWE-22

5950 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-26321MEDIUMThe international version of Xiaomi File Manager has a path traversal vulnerabilityEPSS 0.5%CVE-2026-27040HIGHWordPress WZone plugin <= 14.0.31 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-49766CRITICALWordPress WP User Manager plugin <= 2.9.16 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-4660HIGHGo-getter may allow to arbitrary filesystem reads through git operationsEPSS 0.5%CVE-2026-57331CRITICALWordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2025-34047HIGHLeadsec VPN Path Traversal Arbitrary File ReadEPSS 0.5%CVE-2026-60084HIGHSiYuan before v3.7.4 Arbitrary File Deletion via removeTemplateEPSS 0.5%CVE-2024-47877MEDIUMExtract has insufficient checks allowing attacker to create symlinks outside the extraction directory.EPSS 0.5%CVE-2026-85685HIGHAgentScope through 2.0.7.post1 Arbitrary Directory Copy via add_skillEPSS 0.5%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.5%CVE-2026-84669HIGHA path traversal vulnerability in Jenkins Allure Plugin 2.35.2 and earlier allows attackers with Item/Read permission on jobs that publish AEPSS 0.5%CVE-2026-93712HIGHDancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handlerEPSS 0.5%CVE-2026-75855HIGHArcadeDB before 26.8.1 Path Traversal via create/drop databaseEPSS 0.5%CVE-2025-33035HIGHFile Station 5EPSS 0.5%CVE-2026-17081HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-11419CRITICALPath Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File WriteEPSS 0.5%CVE-2026-55552HIGHYamcs: Unauthenticated Directory TraversalEPSS 0.5%CVE-2026-49247HIGHJellyfin: Potential Authenticated path traversal in /ClientLog/DocumentEPSS 0.5%CVE-2026-17181CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-42756CRITICALWordPress QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion vulnerabilityEPSS 0.5%