Fallos del tipo CWE-22

5970 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-37100HIGHExposure of Sensitive Information to an Unauthorized User in HPE Aruba Networking Private 5G CoreEPSS 0.5%CVE-2025-52574HIGHSysmonElixir path traversal in /read endpoint allows arbitrary file readEPSS 0.5%CVE-2025-33034MEDIUMQsync CentralEPSS 0.5%CVE-2026-14636MEDIUMkirilkirkov Ecommerce-CodeIgniter-Bootstrap Vendor Image Manager AddProduct.php do_upload_others_images path traversalEPSS 0.5%CVE-2026-63739HIGHSurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZEREPSS 0.5%CVE-2026-85272MEDIUMOpen edX Platform: Path traversal via prefix-bypass in safe_extractall Path ValidationEPSS 0.5%CVE-2024-47266LOWImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology AcEPSS 0.5%CVE-2024-7248HIGHComodo Internet Security Pro Directory Traversal Local Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-52890HIGHWekan: Arbitrary file read and server DoS via attachment versions.original.pathEPSS 0.5%CVE-2026-6381HIGHWP Maps < 4.9.3 - Subscriber+ Local File InclusionEPSS 0.5%CVE-2025-28955HIGHWordPress Easy Video Player Wordpress & WooCommerce plugin <= 10.0 - Arbitrary File Download VulnerabilityEPSS 0.5%CVE-2025-29592MEDIUMoasys v1.1 is vulnerable to Directory Traversal in ProcedureController.EPSS 0.5%CVE-2026-47754CRITICALunauthenticated path traversal in Metacat 2.xEPSS 0.5%CVE-2026-17043LOWIBM i is Affected By Multiple Vulnerabilities in Digital Certificate ManagerEPSS 0.5%CVE-2025-31070HIGHWordPress HTML5 Radio Player - WPBakery Page Builder Addon plugin <= 2.5 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2023-46237MEDIUMFOG path traversal via unauthenticated endpointEPSS 0.5%CVE-2026-45496MEDIUMVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2023-39401CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.5%CVE-2023-39400CRITICALParameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be reaEPSS 0.5%CVE-2026-73383MEDIUMWordPress CTX Feed plugin <= 6.6.47 - Arbitrary File Download vulnerabilityEPSS 0.5%