CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3717 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-37231 | WordPress plugin 路径遍历漏洞 — Salon booking system | 8.6 | High | 2024-06-24 |
| CVE-2024-37092 | WordPress Plugin Consulting Elementor Widgets 路径遍历漏洞 — Consulting Elementor Widgets | 8.5 | High | 2024-06-24 |
| CVE-2024-37089 | WordPress plugin 路径遍历漏洞 — Consulting Elementor Widgets | 9.0 | Critical | 2024-06-24 |
| CVE-2024-35781 | WordPress plugin Word Balloon 路径遍历漏洞 — Word Balloon | 6.5 | Medium | 2024-06-21 |
| CVE-2024-35778 | WordPress plugin Slideshow SE 路径遍历漏洞 — Slideshow SE | 6.5 | Medium | 2024-06-21 |
| CVE-2024-4098 | WordPress plugin Shariff Wrapper 安全漏洞 — Shariff Wrapper | 9.8 | Critical | 2024-06-20 |
| CVE-2024-5182 | LocalAI 路径遍历漏洞 — mudler/localai | 7.5 | - | 2024-06-19 |
| CVE-2024-38358 | Wasmer 安全漏洞 — wasmer | 2.9 | Low | 2024-06-19 |
| CVE-2024-36117 | Reposilite 安全漏洞 — reposilite | 8.6 | High | 2024-06-19 |
| CVE-2024-36116 | Reposilite 安全漏洞 — reposilite | 7.5 | High | 2024-06-19 |
| CVE-2024-37902 | Deep Java Library 安全漏洞 — djl | 10.0 | Critical | 2024-06-17 |
| CVE-2024-6044 | D-Link Routers 路径遍历漏洞 — G403 | 6.5 | Medium | 2024-06-17 |
| CVE-2024-2024 | WordPress plugin Folders Pro 安全漏洞 — Folders Pro | 8.8 | High | 2024-06-14 |
| CVE-2024-2023 | WordPress plugin Folders and Folders Pro 安全漏洞 — Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager | 4.3 | Medium | 2024-06-14 |
| CVE-2024-27178 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 7.2 | High | 2024-06-14 |
| CVE-2024-27177 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 7.2 | High | 2024-06-14 |
| CVE-2024-27176 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 7.2 | High | 2024-06-14 |
| CVE-2024-27174 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 9.8 | Critical | 2024-06-14 |
| CVE-2024-27173 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 9.8 | Critical | 2024-06-14 |
| CVE-2024-27145 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 9.8 | Critical | 2024-06-14 |
| CVE-2024-27144 | Toshiba e-STUDIO 安全漏洞 — Toshiba Tec e-Studio multi-function peripheral (MFP) | 9.8 | Critical | 2024-06-14 |
| CVE-2024-34129 | Adobe Acrobat Mobile Sign Android 路径遍历漏洞 — Acrobat Mobile Sign Android | 7.5 | High | 2024-06-13 |
| CVE-2024-37037 | Schneider Electric SAGE RTUs 路径遍历漏洞 — Sage 1410 | 8.1 | High | 2024-06-12 |
| CVE-2024-5154 | CRI-O 安全漏洞 | 8.1 | High | 2024-06-12 |
| CVE-2024-4315 | LoLLMs 安全漏洞 — parisneo/lollms | 9.8AI | CriticalAI | 2024-06-12 |
| CVE-2024-37169 | URL to PNG 安全漏洞 — url-to-png | 5.3 | Medium | 2024-06-10 |
| CVE-2024-36418 | SuiteCRM 安全漏洞 — SuiteCRM | 8.6 | High | 2024-06-10 |
| CVE-2024-35754 | WordPress plugin Ovic Importer 路径遍历漏洞 — Ovic Importer | 7.5 | High | 2024-06-10 |
| CVE-2024-35745 | WordPress plugin Strategery Migrations 路径遍历漏洞 — Strategery Migrations | 7.5 | High | 2024-06-10 |
| CVE-2024-35744 | WordPress plugin Upunzipper 路径遍历漏洞 — Upunzipper | 8.6 | High | 2024-06-10 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3717 条 CVE 漏洞。