CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3521 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-0703 | bootplus 路径遍历漏洞 — bootplus | 4.3 | Medium | 2025-01-24 |
| CVE-2025-24611 | WordPress plugin WP Ultimate Exporter 路径遍历漏洞 — WP Ultimate Exporter | 4.9 | Medium | 2025-01-24 |
| CVE-2024-13409 | WordPress plugin Post Grid, Slider & Carousel Ultimate 路径遍历漏洞 — Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | 7.5 | High | 2025-01-24 |
| CVE-2025-23422 | WordPress plugin Store Locator 路径遍历漏洞 — Store Locator | 7.5 | High | 2025-01-24 |
| CVE-2024-13545 | WordPress plugin Bootstrap Ultimate 路径遍历漏洞 — Bootstrap Ultimate | 9.8 | Critical | 2025-01-24 |
| CVE-2024-42187 | HCL BigFix Patch Management 路径遍历漏洞 — BigFix Patch Management Download Plug-ins | 5.3 | Medium | 2025-01-23 |
| CVE-2025-23562 | WordPress plugin XLSXviewer 路径遍历漏洞 — XLSXviewer | 7.5 | Medium | 2025-01-22 |
| CVE-2025-24019 | YesWiki 路径遍历漏洞 — yeswiki | 7.1 | High | 2025-01-21 |
| CVE-2025-0615 | Qualifio Wheel of Fortune 路径遍历漏洞 — Wheel of fortune | 5.3 | Medium | 2025-01-21 |
| CVE-2025-0614 | Qualifio Wheel of Fortune 路径遍历漏洞 — Wheel of fortune | 5.3 | Medium | 2025-01-21 |
| CVE-2024-45652 | IBM Maximo MXAPIASSET API 路径遍历漏洞 — Maximo Asset Management | 6.5 | Medium | 2025-01-19 |
| CVE-2024-10799 | WordPress plugin Eventer 路径遍历漏洞 — Eventer - WordPress Event & Booking Manager Plugin | 6.5 | Medium | 2025-01-17 |
| CVE-2024-52363 | IBM InfoSphere Information Server 路径遍历漏洞 — InfoSphere Information Server | 6.5 | Medium | 2025-01-17 |
| CVE-2024-48885 | Fortinet多款产品 路径遍历漏洞 — FortiRecorder | 5.2 | Medium | 2025-01-16 |
| CVE-2024-12087 | Rsync 安全漏洞 | 6.5 | Medium | 2025-01-14 |
| CVE-2024-12088 | Rsync 安全漏洞 | 6.5 | Medium | 2025-01-14 |
| CVE-2024-13181 | Ivanti Avalanche 安全漏洞 — Avalanche | 7.3 | High | 2025-01-14 |
| CVE-2024-13180 | Ivanti Avalanche 路径遍历漏洞 — Avalanche | 7.5 | High | 2025-01-14 |
| CVE-2024-13179 | Ivanti Avalanche 安全漏洞 — Avalanche | 7.3 | High | 2025-01-14 |
| CVE-2025-0461 | Lingdang CRM 路径遍历漏洞 — Lingdang CRM | 4.3 | Medium | 2025-01-14 |
| CVE-2024-39786 | WAVLINK AC3000 路径遍历漏洞 — Wavlink AC3000 | 9.1 | Critical | 2025-01-14 |
| CVE-2024-39787 | WAVLINK AC3000 路径遍历漏洞 — Wavlink AC3000 | 9.1 | Critical | 2025-01-14 |
| CVE-2024-33502 | Fortinet FortiManager和FortiAnalyzer 路径遍历漏洞 — FortiManager | 6.4 | Medium | 2025-01-14 |
| CVE-2024-47566 | Fortinet FortiRecorder 路径遍历漏洞 — FortiRecorder | 4.8 | Medium | 2025-01-14 |
| CVE-2024-48884 | Fortinet多款产品 路径遍历漏洞 — FortiProxy | 7.1 | High | 2025-01-14 |
| CVE-2024-36512 | Fortinet FortiManager和FortiAnalyzer 路径遍历漏洞 — FortiManager | 7.0 | High | 2025-01-14 |
| CVE-2024-12083 | Omron NJ/NX-series Machine Automation Controllers 路径遍历漏洞 — Machine Automation Controller NJ-series | 6.6 | Medium | 2025-01-14 |
| CVE-2025-0401 | reggie 路径遍历漏洞 — reggie | 5.3 | Medium | 2025-01-12 |
| CVE-2025-22152 | Atheos 代码注入漏洞 — Atheos | 8.8 | - | 2025-01-10 |
| CVE-2024-11642 | WordPress plugin Post Grid Master 路径遍历漏洞 — Post Grid Master — Post Grids & AJAX Filters | 9.8 | Critical | 2025-01-09 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3521 条 CVE 漏洞。