Falhas do tipo CWE-22

5.868 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-84889HIGHA path traversal vulnerability in file handling components could allow an authenticated attacker to write files to arbitrary locations on the server filesystemEPSS 0.9%CVE-2021-33722—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system has a Path Traversal vulnerability EPSS 0.9%CVE-2024-8875MEDIUMvedees wcms finder.php path traversalEPSS 0.9%CVE-2025-22923HIGHAn issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal and delete files by sending a crafted POST reqEPSS 0.9%CVE-2024-23721HIGHA Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calEPSS 0.9%CVE-2025-15031HIGHPath Traversal Vulnerability in mlflow/mlflowEPSS 0.9%CVE-2025-34058HIGHHikvision Streaming Media Management Server Default Credentials and Authenticated Arbitrary File ReadEPSS 0.9%CVE-2025-29847HIGHApache Linkis: Arbitrary File Read via Double URL Encoding BypassEPSS 0.9%CVE-2026-25475MEDIUMOpenClaw Vulnerable to Local File Inclusion via MEDIA: Path ExtractionEPSS 0.9%CVE-2023-27577MEDIUMPath Traversal Vulnerability in `LESS` Parser allows reading of sensitive server files in flarumEPSS 0.9%CVE-2025-56431HIGHDirectory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via thEPSS 0.9%CVE-2025-56430HIGHDirectory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via thEPSS 0.9%CVE-2026-37531CRITICALAGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367EPSS 0.9%CVE-2026-67200HIGHPerspective 5.0.0 Path Traversal via cwd_static_file_handlerEPSS 0.9%CVE-2026-26064CRITICALcalibre: Path Traversal Vulnerability Enables Arbitrary File Write and Remote Code ExecutionEPSS 0.9%CVE-2022-4583MEDIUMjLEMS JUtil.java unpackJar path traversalEPSS 0.9%CVE-2024-32117MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.EPSS 0.9%CVE-2024-28335CRITICALLektor before 3.3.11 does not sanitize DB path traversal. Thus, shell commands might be executed via a file that is added to the templates dEPSS 0.8%CVE-2023-27475HIGHGoutil vulnerable to path traversal when unzipping filesEPSS 0.8%CVE-2024-32386HIGHDirectory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain senEPSS 0.8%