CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3582 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-47512 | WordPress plugin Tainacan 路径遍历漏洞 — Tainacan | 8.6 | High | 2025-05-23 |
| CVE-2025-47513 | WordPress plugin Infocob CRM Forms 路径遍历漏洞 — Infocob CRM Forms | 4.9 | Medium | 2025-05-23 |
| CVE-2025-47535 | WordPress plugin Opal Woo Custom Product Variation 路径遍历漏洞 — Opal Woo Custom Product Variation | 8.6 | High | 2025-05-23 |
| CVE-2025-47603 | WordPress plugin belingoGeo 路径遍历漏洞 — belingoGeo | 7.5 | High | 2025-05-23 |
| CVE-2025-48273 | WordPress plugin WP Job Portal 路径遍历漏洞 — WP Job Portal | 7.5 | High | 2025-05-23 |
| CVE-2025-4419 | WordPress plugin Hot Random Image 路径遍历漏洞 — Hot Random Image | 4.3 | Medium | 2025-05-22 |
| CVE-2025-3486 | Allegra 路径遍历漏洞 — Allegra | 8.8AI | HighAI | 2025-05-22 |
| CVE-2025-3884 | Cloudera Hue 路径遍历漏洞 — Hue | 7.5AI | HighAI | 2025-05-22 |
| CVE-2025-5029 | Kingdee Cloud Galaxy Private Cloud BBC System 路径遍历漏洞 — Cloud Galaxy Private Cloud BBC System | 5.4 | Medium | 2025-05-21 |
| CVE-2025-4524 | WordPress plugin Madara 路径遍历漏洞 — Madara – Responsive and modern WordPress theme for manga sites | 9.8 | Critical | 2025-05-21 |
| CVE-2025-48017 | Schweitzer Engineering Laboratories SEL Series 安全漏洞 — SEL-5056 Software-Defined Network Flow Controller | 9.0 | Critical | 2025-05-20 |
| CVE-2025-41229 | VMware Cloud Foundation 安全漏洞 — Cloud Foundation | 8.2 | High | 2025-05-20 |
| CVE-2025-3223 | GE Vernova WorkstationST 安全漏洞 — WorkstationST | 5.9 | Medium | 2025-05-19 |
| CVE-2025-32926 | WordPress plugin Grand Restaurant 路径遍历漏洞 — Grand Restaurant | 9.8 | Critical | 2025-05-19 |
| CVE-2025-27566 | appleple a-blog cms 路径遍历漏洞 — a-blog cms | 3.8 | Low | 2025-05-19 |
| CVE-2025-4912 | SourceCodester Student Result Management System 安全漏洞 — Student Result Management System | 5.4 | Medium | 2025-05-19 |
| CVE-2025-4898 | SourceCodester Student Result Management System 安全漏洞 — Student Result Management System | 5.4 | Medium | 2025-05-18 |
| CVE-2025-4893 | CoinExchange_CryptoExchange_Java 路径遍历漏洞 — CoinExchange_CryptoExchange_Java | 6.3 | Medium | 2025-05-18 |
| CVE-2025-4868 | ecommerce-spring-reactjs 路径遍历漏洞 — ecommerce-spring-reactjs | 6.3 | Medium | 2025-05-18 |
| CVE-2025-47273 | setuptools 路径遍历漏洞 — setuptools | 9.8AI | CriticalAI | 2025-05-17 |
| CVE-2025-40629 | PNETLab 路径遍历漏洞 — PNETLab | 7.5AI | HighAI | 2025-05-16 |
| CVE-2025-4720 | SourceCodester Student Result Management System 路径遍历漏洞 — Student Result Management System | 5.4 | Medium | 2025-05-15 |
| CVE-2025-47788 | Atheos 安全漏洞 — Atheos | 9.8AI | CriticalAI | 2025-05-15 |
| CVE-2025-4564 | WordPress plugin TicketBAI Facturas para WooCommerce 路径遍历漏洞 — TicketBAI Facturas para WooCommerce | 9.8 | Critical | 2025-05-15 |
| CVE-2024-13914 | WordPress plugin File Manager Advanced Shortcode 路径遍历漏洞 — File Manager Advanced Shortcode | 7.2 | High | 2025-05-15 |
| CVE-2025-43566 | Adobe ColdFusion 路径遍历漏洞 — ColdFusion | 6.8 | Medium | 2025-05-13 |
| CVE-2025-30387 | Microsoft Azure 路径遍历漏洞 — Azure AI Document Intelligence Studio | 9.8 | Critical | 2025-05-13 |
| CVE-2025-31493 | Kirby 安全漏洞 — kirby | 8.3AI | HighAI | 2025-05-13 |
| CVE-2025-30207 | Kirby 安全漏洞 — kirby | 8.1AI | HighAI | 2025-05-13 |
| CVE-2025-30159 | Kirby 安全漏洞 — kirby | 7.1AI | HighAI | 2025-05-13 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3582 条 CVE 漏洞。