Falhas do tipo CWE-22

6.017 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-15693LOWJCH Optimize 4.2.1 - 5.0.0 - Admin+ Path TraversalEPSS 0.3%CVE-2025-55214MEDIUMCopier safe template has filesystem write access outside destination pathEPSS 0.3%CVE-2026-19532MEDIUMPath Traversal in HAVELSAN's Liman MYSEPSS 0.3%CVE-2026-53951HIGHCopier: trust-prefix bypass via path traversal runs tasks unpromptedEPSS 0.3%CVE-2022-42280HIGHNVIDIA BMC contains a vulnerability in SPX REST auth handler, where an un-authorized attacker can exploit a path traversal, which may lead tEPSS 0.3%CVE-2026-84069MEDIUMWebFacing Email Accounts for cPanel 5.3 - 5.3.6 - Unauthenticated LFI via assets/index.phpEPSS 0.3%CVE-2024-27871MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app mayEPSS 0.3%CVE-2026-51873HIGHDevika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside tEPSS 0.3%CVE-2026-14967LOWPath traversal in github_workflows allows writing artifacts outside output directoryEPSS 0.3%CVE-2026-81716HIGHopenssl_encrypt before 1.4.9 Plugin Sandbox Path TraversalEPSS 0.3%CVE-2025-10406MEDIUMBlindMatrix e-Commerce < 3.1 - Contributor+ LFIEPSS 0.3%CVE-2024-41938MEDIUMA vulnerability has been identified in SINEC NMS (All versions < V3.0). The importCertificate function of the SINEC NMS Control web applicatEPSS 0.3%CVE-2026-22625MEDIUMImproper handling of filenames in certain HIKSEMI NAS products may lead to the exposure of sensitive system files.EPSS 0.3%CVE-2026-59732MEDIUMrclone archive extract allows S3 destination prefix escape via crafted archive pathsEPSS 0.3%CVE-2025-55201HIGHCopier safe template has arbitrary filesystem read/write accessEPSS 0.3%CVE-2021-36286HIGHDell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability thaEPSS 0.3%CVE-2025-62851MEDIUMLicense CenterEPSS 0.3%CVE-2026-101044HIGHpacquet before 12.0.0-alpha.5 Path Traversal via lockfile aliasEPSS 0.3%CVE-2026-19722MEDIUMWPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup RestoreEPSS 0.3%CVE-2026-40987HIGHRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalizationEPSS 0.3%