Fallos del tipo CWE-22

5967 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-100636HIGHSiYuan before v3.8.4 Path Traversal via exportBrowserHTML folderEPSS 0.5%CVE-2025-27142MEDIUMLocalSend path traversal vulnerability in the file upload endpoint allows nearby devices to execute arbitrary commandsEPSS 0.5%CVE-2026-71493MEDIUMInfracost: Arbitrary file read via config-template readFile symlink traversalEPSS 0.5%CVE-2026-45568CRITICALzrok Python ProxyShare can be used as an SSRF proxy through absolute URL pathsEPSS 0.5%CVE-2026-32637MEDIUMVelero vulnerable to file path traversal when extracting from backup's tarballEPSS 0.5%CVE-2026-37066MEDIUMPath traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 aEPSS 0.5%CVE-2026-21857HIGHRedaxo has Path Traversal in Backup Addon Leading to Arbitrary File ReadEPSS 0.5%CVE-2026-27704MEDIUMDart SDK and Flutter SDK have Zip slip in Dart Pub package extractionEPSS 0.5%CVE-2026-44635HIGHKysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`EPSS 0.5%CVE-2024-34551CRITICALWordPress Stockholm theme <= 9.6 - Unauthenticated Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-6496MEDIUMprasathmani TinyFileManager POST Parameter filemanager.php path traversalEPSS 0.5%CVE-2026-18959MEDIUMyushine InnoShop Files Endpoint panel-api.php destroyFiles path traversalEPSS 0.5%CVE-2021-27278HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-49141. An attacker muEPSS 0.5%CVE-2024-35677CRITICALWordPress MegaMenu plugin <= 2.3.12 - Unauthenticated Local File Inclusion vulnerabilityEPSS 0.5%CVE-2026-7024MEDIUMrawchen sims deleteFileServlet Endpoint DeleteFileServlet.java path traversalEPSS 0.5%CVE-2026-18644MEDIUMdanpros HTMLy Delete Username Endpoint htmly.php unlink path traversalEPSS 0.5%CVE-2025-41758HIGHArbitrary Write with wwwupload.cgiEPSS 0.5%CVE-2025-1127CRITICALCombination Path Traversal and Concurrent Execution vulnerability exists within the embedded web serverEPSS 0.5%CVE-2025-41757HIGHArbitrary Write with ubr-restoreEPSS 0.5%CVE-2026-18645MEDIUMdanpros HTMLy Admin Content Endpoint admin.php add_content path traversalEPSS 0.5%