Falhas do tipo CWE-22

5.975 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-29844MEDIUMA vulnerability in FileStation file cgi allows remote authenticated users to read file metadata and path information.EPSS 0.4%CVE-2026-41656MEDIUMAdmidio: Path Traversal via Unvalidated `name` Parameter in Document Add Mode Enables Arbitrary Server File ReadEPSS 0.4%CVE-2026-35454HIGHCode Extension Marketplace has a Zip Slip Path TraversalEPSS 0.4%CVE-2025-29845MEDIUMA vulnerability in VideoPlayer2 subtitle cgi allows remote authenticated users to read .srt files.EPSS 0.4%CVE-2025-68907HIGHWordPress Hostme v2 theme <= 7.0 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2026-55677HIGHEcho: Encoded slash (%2F) bypasses route-level protection and exposes static filesEPSS 0.4%CVE-2026-47735HIGHArc has an authenticated arbitrary local-file read via DuckDB I/O functions that bypasses RBAC table-level checksEPSS 0.4%CVE-2026-104983MEDIUMLinux Mint Xreader PDF Attachment Saving ev-window.c g_file_get_child path traversalEPSS 0.4%CVE-2026-42496CRITICALArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directoryEPSS 0.4%CVE-2022-44749MEDIUMOpening workflows from untrusted resources may override arbitrary file system contentsEPSS 0.4%CVE-2025-52450MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux EPSS 0.4%CVE-2022-36007MEDIUMPartial Path Traversal in com.github.jlangch:veniceEPSS 0.4%CVE-2025-22397MEDIUMDell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 through 7.20.10.50 and DEPSS 0.4%CVE-2024-32729HIGHWordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Download vulnerabilityEPSS 0.4%CVE-2026-40163HIGHSaltcorn has an Unauthenticated Path Traversal in sync endpoints allows arbitrary file write and directory readEPSS 0.4%CVE-2026-55393CRITICALLocal File Inclusion in Teledyne FLIR Robots running Aware2EPSS 0.4%CVE-2025-59566HIGHWordPress Workreap (theme's plugin) plugin <= 3.3.5 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-58959HIGHWordPress Taskbot plugin <= 6.4 - Arbitrary File Deletion vulnerabilityEPSS 0.4%CVE-2025-42906MEDIUMDirectory Traversal vulnerability in SAP Commerce CloudEPSS 0.4%CVE-2026-82521MEDIUMparsedmarc 9.0.6 < 11.0.1 Path Traversal via Forensic Report SubjectEPSS 0.4%