Falhas do tipo CWE-22

5.925 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-17173MEDIUMIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.7%CVE-2026-68062MEDIUMSKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can logEPSS 0.7%CVE-2025-41428MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitraEPSS 0.7%CVE-2025-12638HIGHPath Traversal Vulnerability in keras-team/keras via Tar Archive Extraction in keras.utils.get_file()EPSS 0.7%CVE-2026-9195CRITICALCross-site scripting in Progress MarkLogic Server Query ConsoleEPSS 0.7%CVE-2024-48224HIGHFunadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile.EPSS 0.7%CVE-2024-10585MEDIUMInfiniteWP Client <= 1.13.0 - Unauthenticated Limited Directory Traversal to Arbitrary .txt File ReadingEPSS 0.7%CVE-2025-65077HIGHRelative path traversal vulnerability in Embedded Solutions FrameworkEPSS 0.7%CVE-2025-22152CRITICALImproper Path Validation Enables Path Traversal in Multiple Components in AtheosEPSS 0.7%CVE-2025-69770CRITICALA zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commandEPSS 0.7%CVE-2021-47977HIGHWordPress Anti-Malware Security Bruteforce Firewall <= 4.20.72 Directory TraversalEPSS 0.7%CVE-2024-32023MEDIUMKohya_ss vulnerable to path injection in `common_gui.py` `find_and_replace` function (`GHSL-2024-024`)EPSS 0.7%CVE-2026-25525MEDIUMOpenMage LTS has Path Traversal Filter Bypass in Dataflow ModuleEPSS 0.7%CVE-2026-45727HIGHCloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletionEPSS 0.7%CVE-2026-63312HIGHNLTK StreamBackedCorpusView Bypasses pathsec.ENFORCE Arbitrary File ReadEPSS 0.7%CVE-2025-66687HIGHDoom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game filesEPSS 0.7%CVE-2026-41058HIGHAVideo has an incomplete fix for CVE-2026-33293 (Path Traversal) in AVideoEPSS 0.7%CVE-2026-35214HIGHBudibase: Path traversal in plugin file upload enables arbitrary directory deletion and file writeEPSS 0.7%CVE-2026-88937HIGHknowns through 0.33.0 Path Traversal via Template EngineEPSS 0.7%CVE-2026-62384HIGHNLTK FramenetCorpusReader Symlink Sandbox Bypass before 3.10.2EPSS 0.7%