Fallos del tipo CWE-22

5964 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-4660HIGHGo-getter may allow to arbitrary filesystem reads through git operationsEPSS 0.5%CVE-2026-93712HIGHDancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handlerEPSS 0.5%CVE-2026-17181CRITICALIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2024-47877MEDIUMExtract has insufficient checks allowing attacker to create symlinks outside the extraction directory.EPSS 0.5%CVE-2026-42757CRITICALWordPress WebinarIgnition plugin < 4.08.253 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-69089HIGHGrav CMS before 2.0.11 Path Traversal via watermarkEPSS 0.5%CVE-2026-17081HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-60084HIGHSiYuan before v3.7.4 Arbitrary File Deletion via removeTemplateEPSS 0.5%CVE-2026-75855HIGHArcadeDB before 26.8.1 Path Traversal via create/drop databaseEPSS 0.5%CVE-2025-31825MEDIUMWordPress Category Icon plugin <= 1.0.1 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-49766CRITICALWordPress WP User Manager plugin <= 2.9.16 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-57331CRITICALWordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-27040HIGHWordPress WZone plugin <= 14.0.31 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-42756CRITICALWordPress QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly plugin <= 3.2.7 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2026-55552HIGHYamcs: Unauthenticated Directory TraversalEPSS 0.5%CVE-2023-3331—Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG18EPSS 0.5%CVE-2024-47563MEDIUMA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate aEPSS 0.5%CVE-2026-23644HIGHesm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packagesEPSS 0.5%CVE-2025-24961MEDIUMInsecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3ProxyEPSS 0.5%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.5%