CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3481 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-43889 | Dell PowerProtect Data Domain 路径遍历漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release | 5.3 | Medium | 2025-10-07 |
| CVE-2025-43934 | Dell PowerProtect Data Domain 路径遍历漏洞 — PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release | 6.0 | Medium | 2025-10-07 |
| CVE-2025-40889 | Nozomi Networks Guardian和Nozomi Networks CMC 路径遍历漏洞 — Guardian | 8.1 | High | 2025-10-07 |
| CVE-2025-3718 | Nozomi Networks CMC 路径遍历漏洞 — Guardian | 7.9 | High | 2025-10-07 |
| CVE-2025-11337 | Four-Faith Water Conservancy Informatization Platform 路径遍历漏洞 — Water Conservancy Informatization Platform | 5.3 | Medium | 2025-10-06 |
| CVE-2025-11336 | Four-Faith Water Conservancy Informatization Platform 路径遍历漏洞 — Water Conservancy Informatization Platform | 5.3 | Medium | 2025-10-06 |
| CVE-2025-58591 | SICK AG Baggage Analytics 安全漏洞 — Baggage Analytics | 6.5 | Medium | 2025-10-06 |
| CVE-2025-58590 | SICK AG Baggage Analytics 安全漏洞 — Baggage Analytics | 6.5 | Medium | 2025-10-06 |
| CVE-2025-8917 | clearml 安全漏洞 — allegroai/clearml | 9.8AI | CriticalAI | 2025-10-05 |
| CVE-2025-8406 | ZenML 安全漏洞 — zenml-io/zenml | 9.8AI | CriticalAI | 2025-10-05 |
| CVE-2025-47211 | QNAP operating system 路径遍历漏洞 — QTS | 6.5 | - | 2025-10-03 |
| CVE-2025-33034 | QNAP Qsync Central 路径遍历漏洞 — Qsync Central | 7.5 | - | 2025-10-03 |
| CVE-2025-61666 | Traccar 安全漏洞 — traccar | 9.1AI | CriticalAI | 2025-10-02 |
| CVE-2025-59744 | AndSoft e-TMS 路径遍历漏洞 — e-TMS | 5.3 | - | 2025-10-02 |
| CVE-2025-54293 | LXD 安全漏洞 — LXD | 6.5AI | MediumAI | 2025-10-02 |
| CVE-2025-54292 | LXD 安全漏洞 — LXD | 8.1AI | HighAI | 2025-10-02 |
| CVE-2025-11221 | GTONE ChangeFlow 安全漏洞 — ChangeFlow | 8.8 | High | 2025-10-02 |
| CVE-2025-11182 | GTONE ChangeFlow 安全漏洞 — ChangeFlow | 6.5 | Medium | 2025-10-02 |
| CVE-2025-58769 | Auth0-PHP 安全漏洞 — laravel-auth0 | 3.3 | Low | 2025-10-01 |
| CVE-2025-11233 | Rust 安全漏洞 — std | 9.8AI | CriticalAI | 2025-10-01 |
| CVE-2025-8559 | WordPress plugin All in One Music Player 路径遍历漏洞 — All in One Music Player | 6.5 | Medium | 2025-09-30 |
| CVE-2025-61586 | FreshRSS 安全漏洞 — FreshRSS | 5.3 | - | 2025-09-29 |
| CVE-2025-43813 | Liferay Portal和Liferay DXP 路径遍历漏洞 — Portal | 8.2AI | HighAI | 2025-09-29 |
| CVE-2025-11139 | Bjskzy Zhiyou ERP 路径遍历漏洞 — Zhiyou ERP | 6.3 | Medium | 2025-09-29 |
| CVE-2025-11034 | Dibo Data Decision Making System 路径遍历漏洞 — Data Decision Making System | 4.3 | Medium | 2025-09-26 |
| CVE-2025-11031 | DataTables 安全漏洞 — DataTables | 5.3 | Medium | 2025-09-26 |
| CVE-2025-11018 | Four-Faith Water Conservancy Informatization Platform 路径遍历漏洞 — Water Conservancy Informatization Platform | 5.3 | Medium | 2025-09-26 |
| CVE-2025-11016 | kodbox 路径遍历漏洞 — kodbox | 4.3 | Medium | 2025-09-26 |
| CVE-2025-59002 | WordPress plugin BM Content Builder 路径遍历漏洞 — BM Content Builder | 7.7 | High | 2025-09-26 |
| CVE-2025-10307 | WordPress plugin Backuply 路径遍历漏洞 — Backuply – Backup, Restore, Migrate and Clone | 6.5 | Medium | 2025-09-26 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3481 条 CVE 漏洞。