CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3717 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-7600 | Logsign Unified SecOps Platform 路径遍历漏洞 — Unified SecOps Platform | 8.1AI | HighAI | 2024-08-21 |
| CVE-2024-7782 | WordPress plugin Contact Form by Bit Form 安全漏洞 — Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | 8.7 | High | 2024-08-20 |
| CVE-2024-7777 | WordPress plugin Contact Form by Bit Form 安全漏洞 — Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder | 9.0 | Critical | 2024-08-20 |
| CVE-2024-7928 | FastAdmin 路径遍历漏洞 — FastAdmin | 4.3 | Medium | 2024-08-19 |
| CVE-2024-7927 | ZZCMS 路径遍历漏洞 — ZZCMS | 7.3 | High | 2024-08-19 |
| CVE-2024-7926 | ZZCMS 路径遍历漏洞 — ZZCMS | 7.3 | High | 2024-08-19 |
| CVE-2024-43345 | WordPress plugin Landing Page Builder 路径遍历漏洞 — Landing Page Builder | 7.5 | High | 2024-08-19 |
| CVE-2024-43328 | WordPress plugin EmbedPress 路径遍历漏洞 — EmbedPress | 8.3 | High | 2024-08-19 |
| CVE-2024-7924 | ZZCMS 路径遍历漏洞 — ZZCMS | 5.3 | Medium | 2024-08-19 |
| CVE-2024-43281 | WordPress plugin Void Elementor Post Grid Addon for Elementor Page builder路径遍历漏洞 — Void Elementor Post Grid Addon for Elementor Page builder | 5.3 | Medium | 2024-08-19 |
| CVE-2024-43271 | WordPress plugin Woo Products Widgets For Elementor 路径遍历漏洞 — Woo Products Widgets For Elementor | 8.5 | High | 2024-08-19 |
| CVE-2024-43248 | WordPress plugin Bit Form Pro 路径遍历漏洞 — Bit Form Pro | 8.6 | High | 2024-08-19 |
| CVE-2024-43232 | WordPress plugin Timeline and History slider 路径遍历漏洞 — Timeline and History slider | 8.5 | High | 2024-08-19 |
| CVE-2024-43221 | WordPress plugin JetGridBuilder 路径遍历漏洞 — JetGridBuilder | 8.5 | High | 2024-08-19 |
| CVE-2023-5505 | WordPress plugin BackWPup 安全漏洞 — BackWPup – WordPress Backup & Restore Plugin | 6.8 | Medium | 2024-08-17 |
| CVE-2024-43395 | CraftOS-PC 2 安全漏洞 — craftos2 | 8.2 | High | 2024-08-16 |
| CVE-2024-7145 | WordPress plugin JetElements 安全漏洞 — JetElements | 8.8 | High | 2024-08-16 |
| CVE-2024-7146 | WordPress plugin JetTabs for Elementor 安全漏洞 — JetTabs | 8.8 | High | 2024-08-16 |
| CVE-2024-7263 | Kingsoft WPS Office 安全漏洞 — WPS Office | 7.8AI | HighAI | 2024-08-15 |
| CVE-2024-7262 | Kingsoft WPS Office 安全漏洞 — WPS Office | 7.1AI | HighAI | 2024-08-15 |
| CVE-2024-39399 | Adobe Commerce 路径遍历漏洞 — Adobe Commerce | 7.7 | High | 2024-08-14 |
| CVE-2024-39406 | Adobe Commerce 路径遍历漏洞 — Adobe Commerce | 6.8 | Medium | 2024-08-14 |
| CVE-2024-7741 | Wanglong LTcms路径遍历漏洞 — ltcms | 5.3 | Medium | 2024-08-13 |
| CVE-2024-6618 | Ocean Data Systems Dream Report 路径遍历漏洞 — Dream Report 2023 | 8.4AI | HighAI | 2024-08-13 |
| CVE-2024-43165 | WordPress plugin WPSection 路径遍历漏洞 — WPSection | 6.5 | Medium | 2024-08-13 |
| CVE-2024-43140 | WordPress plugin Ultimate Bootstrap Elements for Elementor 路径遍历漏洞 — Ultimate Bootstrap Elements for Elementor | 7.5 | High | 2024-08-13 |
| CVE-2024-43138 | WordPress plugin Event Manager for WooCommerce 安全漏洞 — Event Manager for WooCommerce | 6.5 | Medium | 2024-08-13 |
| CVE-2024-43135 | WordPress plugin WPCafe 路径遍历漏洞 — WPCafe | 7.5 | High | 2024-08-13 |
| CVE-2024-43129 | WordPress plugin BetterDocs 路径遍历漏洞 — BetterDocs | 6.5 | Medium | 2024-08-13 |
| CVE-2024-39651 | WordPress plugin WooCommerce PDF Vouchers 路径遍历漏洞 — WooCommerce PDF Vouchers | 8.6 | High | 2024-08-13 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3717 条 CVE 漏洞。