CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3717 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-5982 | ChuanhuChatGPT 路径遍历漏洞 — gaizhenbiao/chuanhuchatgpt | 9.8AI | CriticalAI | 2024-10-29 |
| CVE-2024-49771 | MPXJ 路径遍历漏洞 — mpxj | 5.3 | Medium | 2024-10-28 |
| CVE-2024-49766 | Werkzeug 路径遍历漏洞 — werkzeug | 7.5 | - | 2024-10-25 |
| CVE-2024-10011 | WordPress plugin BuddyPress 安全漏洞 — BuddyPress | 8.1 | High | 2024-10-25 |
| CVE-2024-45842 | Sharp MFP 安全漏洞 — Sharp Digital Full-color MFPs and Monochrome MFPs | 5.3 | Medium | 2024-10-25 |
| CVE-2024-49760 | OpenRefine 路径遍历漏洞 — OpenRefine | 7.1 | High | 2024-10-24 |
| CVE-2024-48931 | ZimaOS 安全漏洞 — ZimaOS | 7.5 | High | 2024-10-24 |
| CVE-2024-10313 | iniNet Solutions SpiderControl SCADA PC HMI Editor 路径遍历漏洞 — SpiderControl SCADA PC HMI Editor | 8.0 | High | 2024-10-24 |
| CVE-2024-41717 | Kieback&Peter DDC4000 路径遍历漏洞 — DDC4040e | 9.8 | Critical | 2024-10-22 |
| CVE-2024-35308 | Pandora FMS 安全漏洞 — Pandora FMS | 6.5AI | MediumAI | 2024-10-22 |
| CVE-2024-49366 | Nginx UI 路径遍历漏洞 — nginx-ui | 9.8AI | CriticalAI | 2024-10-21 |
| CVE-2024-49286 | WordPress plugin SSV Events 路径遍历漏洞 — SSV Events | 9.6 | Critical | 2024-10-20 |
| CVE-2024-10100 | GPT Academic 路径遍历漏洞 — binary-husky/gpt_academic | 7.5AI | HighAI | 2024-10-17 |
| CVE-2024-49285 | WordPress plugin SSV MailChimp 安全漏洞 — SSV MailChimp | 7.5 | High | 2024-10-17 |
| CVE-2024-49287 | WordPress plugin PDF-Rechnungsverwaltung 路径遍历漏洞 — PDF-Rechnungsverwaltung | 7.5 | High | 2024-10-17 |
| CVE-2024-49315 | WordPress plugin FREE DOWNLOAD MANAGER 安全漏洞 — FREE DOWNLOAD MANAGER | 8.6 | High | 2024-10-17 |
| CVE-2024-49245 | WordPress plugin Ahime Image Printer 路径遍历漏洞 — Ahime Image Printer | 7.5 | High | 2024-10-16 |
| CVE-2024-47351 | WordPress plugin MaxSlider 路径遍历漏洞 — MaxSlider | 7.5 | High | 2024-10-16 |
| CVE-2024-47645 | WordPress plugin Top Bar – PopUps 路径遍历漏洞 — Top Bar – PopUps – by WPOptin | 7.5 | High | 2024-10-16 |
| CVE-2024-45711 | SolarWinds Serv-U 路径遍历漏洞 — Serv-U | 7.5 | High | 2024-10-16 |
| CVE-2019-25213 | WordPress plugin Advanced Access Manager 路径遍历漏洞 — Advanced Access Manager – Access Governance for WordPress | 9.8 | Critical | 2024-10-16 |
| CVE-2024-48914 | Vendure 输入验证错误漏洞 — vendure | 9.1 | Critical | 2024-10-15 |
| CVE-2024-9676 | Podman 路径遍历漏洞 | 6.5 | Medium | 2024-10-15 |
| CVE-2024-46898 | SHIRASAGI 安全漏洞 — SHIRASAGI | 7.5 | - | 2024-10-15 |
| CVE-2024-0129 | NVIDIA NeMo 安全漏洞 — NeMo | 6.3 | Medium | 2024-10-15 |
| CVE-2024-9047 | WordPress plugin WordPress File Upload 路径遍历漏洞 — Iptanus File Upload | 9.8 | Critical | 2024-10-12 |
| CVE-2024-47877 | Extract 安全漏洞 — extract | 6.5AI | MediumAI | 2024-10-11 |
| CVE-2024-6971 | LoLLMs 路径遍历漏洞 — parisneo/lollms | 8.4AI | HighAI | 2024-10-11 |
| CVE-2024-7514 | WordPress plugin Comments Import & Export 路径遍历漏洞 — Comments Import & Export | 6.5 | Medium | 2024-10-11 |
| CVE-2024-47164 | Gradio 路径遍历漏洞 — gradio | 7.4AI | HighAI | 2024-10-10 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3717 条 CVE 漏洞。