Falhas do tipo CWE-22

5.925 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-1785MEDIUMDownload Manager <= 3.3.08 - Authenticated (Author+) Path Traversal to Limited File OverwriteEPSS 0.7%CVE-2023-23608NONEspotipy Path traversal vulnerability that may lead to type confusion in URI handling codeEPSS 0.7%CVE-2024-24869HIGHWordPress Total Upkeep plugin <= 1.15.8 - Arbitrary File Download vulnerabilityEPSS 0.7%CVE-2025-34518HIGHIlevia EVE X1 Server 4.7.18.0.eden Relative Path TraversalEPSS 0.7%CVE-2025-34517HIGHIlevia EVE X1 Server 4.7.18.0.eden Absolute Path TraversalEPSS 0.7%CVE-2024-29502MEDIUMAn issue in Secure Lockdown Multi Application Edition v2.00.219 allows attackers to read arbitrary files via using UNC paths.EPSS 0.7%CVE-2022-4778MEDIUMpath traversal in elvexys StreamX using StreamView HTML component with public web server featureEPSS 0.7%CVE-2019-25671HIGHVA MAX 8.3.4 Remote Code Execution via changeip.phpEPSS 0.7%CVE-2023-29962MEDIUMS-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.EPSS 0.7%CVE-2026-82253HIGHgitoxide before 0.82.0 Path Traversal via Submodule Name Validation BypassEPSS 0.7%CVE-2026-16777MEDIUMStore Exporter <= 2.8.0 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read and Arbitrary File Deletion via 'filename' ParameterEPSS 0.7%CVE-2026-2731CRITICALUnauthenticated RCE in Dynamicweb 9 and Dynamicweb 8EPSS 0.7%CVE-2026-28462HIGHOpenClaw < 2026.2.13 - Path Traversal in Trace and Download Output PathsEPSS 0.7%CVE-2024-6648HIGHPath Traversal in AP Page BuilderEPSS 0.7%CVE-2025-2817HIGHPrivilege escalation in Thunderbird UpdaterEPSS 0.7%CVE-2024-57549HIGHCMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request.EPSS 0.7%CVE-2025-49559MEDIUMAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.7%CVE-2026-17266MEDIUMIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.7%CVE-2026-17173MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.7%CVE-2022-4878MEDIUMJATOS ZIP ZipUtil.java ZipUtil path traversalEPSS 0.7%