Fallos del tipo CWE-22

5973 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-55201HIGHEvil-WinRM - Path Traversal in download_dir() FunctionEPSS 0.5%CVE-2026-1810MEDIUMbolo-blog bolo-solo ZIP File BackupService.java unpackFilteredZip path traversalEPSS 0.5%CVE-2026-39378MEDIUMnbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image EmbeddingEPSS 0.5%CVE-2024-0980HIGHThe Auto-update service for Okta Verify for Windows is vulnerable to two flaws which in combination could be used to execute arbitrary code.EPSS 0.5%CVE-2026-32885MEDIUMDDEV has ZipSlip path traversal in tar and zip archive extractionEPSS 0.5%CVE-2026-42028MEDIUMnovaGallery: Unauthenticated Path Traversal in Album and Cached Image Routes Allows Reading Images Outside Gallery RootEPSS 0.5%CVE-2026-43791MEDIUMA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.5%CVE-2023-25750MEDIUMUnder certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulneEPSS 0.5%CVE-2025-59744HIGHMultiple vulnerabilities in AndSoft's e-TMSEPSS 0.5%CVE-2025-61586MEDIUMFreshRSS is vulnerable to directory enumeration by setting path in its theme fieldEPSS 0.5%CVE-2023-42804LOWBigBlueButton Path Traversal – Reading Certain File ExtensionsEPSS 0.5%CVE-2025-60574HIGHA Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles/" path, which failsEPSS 0.5%CVE-2025-60024HIGHMultiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet EPSS 0.5%CVE-2025-7896MEDIUMharry0703 MoneyPrinterTurbo video.py delete_video path traversalEPSS 0.5%CVE-2025-10233MEDIUMkalcaddle kodbox editor.class.php fileSave path traversalEPSS 0.5%CVE-2026-47682HIGHCVAT: Missing path-containment validation in multiple entry points allows arbitrary path writesEPSS 0.5%CVE-2026-40605MEDIUMTautulli Vulnerable to Authenticated Path Traversal in Cache Deletion APIEPSS 0.5%CVE-2026-39405CRITICALFrappe has Path Transversal via SCORMEPSS 0.5%CVE-2023-45026MEDIUMQTS, QuTS hero, QuTScloudEPSS 0.5%CVE-2025-4893MEDIUMjammy928 CoinExchange_CryptoExchange_Java File Upload Endpoint UploadFileUtil.java uploadLocalImage path traversalEPSS 0.5%