Falhas do tipo CWE-22

5.991 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2026-86087MEDIUMIBM® Db2® could allow an authenticated user to send a specially crafted request to write arbitrary files on the systemEPSS 0.3%CVE-2025-30470MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 1EPSS 0.3%CVE-2026-18465MEDIUMWP Maps Pro < 6.1.3 - Unauthenticated Local File InclusionEPSS 0.3%CVE-2026-71426HIGHGetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" fieldEPSS 0.3%CVE-2025-53080HIGHImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Samsung DMS(Data Management Server) allows authenticated aEPSS 0.3%CVE-2026-23484MEDIUMBlinko: Authenticated Arbitrary File Write - saveDevPluginEPSS 0.3%CVE-2026-14470MEDIUMLangflow OSS is affected by arbitrary file read due to path traversal vulnerabilities in file and knowledge base componentsEPSS 0.3%CVE-2026-34371MEDIUMLibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename TraversalEPSS 0.3%CVE-2026-12089MEDIUMWS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File ReadEPSS 0.3%CVE-2026-64777MEDIUMA malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolEPSS 0.3%CVE-2026-48482CRITICALGLPI: RCE via Form importEPSS 0.3%CVE-2024-36795MEDIUMInsecure permissions in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to access URLs and directories embedded within the fiEPSS 0.3%CVE-2026-86334MEDIUMCLI Path Traversal via Content-Disposition in LXD Image Export/CopyEPSS 0.3%CVE-2026-65829MEDIUMMPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readersEPSS 0.3%CVE-2026-103754MEDIUMAnsible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directoryEPSS 0.3%CVE-2026-96884MEDIUMMantisZip Preview MainWindow.UI.cs Path.Combine path traversalEPSS 0.3%CVE-2018-25421HIGHOpen STA Manager 2.3 Arbitrary File Download via Path TraversalEPSS 0.3%CVE-2025-54959MEDIUMPowered BLUE Server versions 0.20130927 and prior contain a path traversal vulnerability. If this vulnerability is exploited, an arbitrary fEPSS 0.3%CVE-2021-35230MEDIUMUnquoted Path Vulnerability (SMB Login) in Kiwi CatToolsEPSS 0.3%CVE-2024-2045MEDIUMSession 1.17.5 - LFR via chat attachmentEPSS 0.3%