Falhas do tipo CWE-22

5.950 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-33035HIGHFile Station 5EPSS 0.5%CVE-2026-17081HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-57331CRITICALWordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerabilityEPSS 0.5%CVE-2024-47563MEDIUMA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate aEPSS 0.5%CVE-2026-23644HIGHesm.sh has path traversal in `extractPackageTarball` that enables file writes from malicious packagesEPSS 0.5%CVE-2026-55389HIGHdatamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`EPSS 0.5%CVE-2023-3331—Improper Limitation of a Pathname to a Restricted Directory vulnerability in NEC Corporation Aterm Aterm WG2600HP2, WG2600HP, WG2200HP, WG18EPSS 0.5%CVE-2025-27785HIGHApplio allows arbitrary file read in train.py export_index functionEPSS 0.5%CVE-2025-24961MEDIUMInsecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3ProxyEPSS 0.5%CVE-2026-74038HIGHWazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent EnrollmentEPSS 0.5%CVE-2026-53940HIGHConda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementationEPSS 0.5%CVE-2024-46954HIGHAn issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ..EPSS 0.5%CVE-2026-33027MEDIUMNginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration DirectoryEPSS 0.5%CVE-2024-43797MEDIUMPath Traversal in audiobookshelfEPSS 0.5%CVE-2026-82111MEDIUMiswalle getnote-mcp upload_image index.ts fs.readFileSync path traversalEPSS 0.5%CVE-2026-7182CRITICALPath Traversal in DiagramEPSS 0.5%CVE-2026-40611HIGHLego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 ProviderEPSS 0.5%CVE-2026-6320HIGHSalon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path TraversalEPSS 0.5%CVE-2026-67185HIGHTinyWeb 0.0.8 Path Traversal via URL Path ComponentEPSS 0.5%CVE-2025-27786HIGHApplio allows arbitrary file removal in core.pyEPSS 0.5%