Fallos del tipo CWE-22

5979 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-35454HIGHCode Extension Marketplace has a Zip Slip Path TraversalEPSS 0.4%CVE-2026-55677HIGHEcho: Encoded slash (%2F) bypasses route-level protection and exposes static filesEPSS 0.4%CVE-2025-29845MEDIUMA vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.EPSS 0.4%CVE-2026-47735HIGHArc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksEPSS 0.4%CVE-2026-104983MEDIUMLinux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversalEPSS 0.4%CVE-2025-68907HIGHWordPress Hostme v2 theme <= 7.0 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-41656MEDIUMAdmidio: Path Traversal via Unvalidated `name` Parameter in Document Add Mode Enables Arbitrary Server File ReadEPSS 0.4%CVE-2025-29844MEDIUMA vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.EPSS 0.4%CVE-2026-40163HIGHSaltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory readEPSS 0.4%CVE-2024-32729HIGHWordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-42496CRITICALArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directoryEPSS 0.4%CVE-2025-22397MEDIUMDell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and DEPSS 0.4%CVE-2025-52450MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux EPSS 0.4%CVE-2022-36007MEDIUMPartial Path Traversal in com.github.jlangch:veniceEPSS 0.4%CVE-2022-44749MEDIUMOpening workflows from untrusted resources may override arbitrary file system contentsEPSS 0.4%CVE-2025-59566HIGHWordPress Workreap (theme's plugin) plugin <= 3.3.5 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2024-4556MEDIUMDirectory traversal vulnerability in NetIQ Access ManagerEPSS 0.4%CVE-2026-82521MEDIUMparsedmarc 9.0.6 < 11.0.1 Path Traversal via Forensic Report SubjectEPSS 0.4%CVE-2026-55393CRITICALLocal File Inclusion in Teledyne FLIR Robots running Aware2EPSS 0.4%CVE-2025-42906MEDIUMDirectory Traversal vulnerability in SAP Commerce CloudEPSS 0.4%