CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3710 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-3783 | WBSAirback 路径遍历漏洞 — White Bear Solutions | 7.7 | High | 2024-04-15 |
| CVE-2023-52144 | WordPress Plugin Product Feed Manager 路径遍历漏洞 — Product Feed Manager | 5.5 | Medium | 2024-04-15 |
| CVE-2024-3737 | nginxWebUI 路径遍历漏洞 — nginxWebUI | 6.3 | Medium | 2024-04-13 |
| CVE-2024-31462 | Stable Diffusion web UI 安全漏洞 — stable-diffusion-webui | 6.3 | Medium | 2024-04-12 |
| CVE-2024-1511 | LoLLMs 路径遍历漏洞 — parisneo/lollms-webui | 8.8AI | HighAI | 2024-04-10 |
| CVE-2024-1728 | gradio 路径遍历漏洞 — gradio-app/gradio | 9.8AI | CriticalAI | 2024-04-10 |
| CVE-2024-31287 | WordPress Plugin Media Library Folders 路径遍历漏洞 — Media Library Folders | 6.5 | Medium | 2024-04-10 |
| CVE-2024-31240 | WordPress Plugin WP Poll Maker 路径遍历漏洞 — WP Poll Maker | 7.7 | High | 2024-04-10 |
| CVE-2024-1790 | WordPress Plugin WordPress Infinite Scroll 安全漏洞 — Ajax Load More – Infinite Scroll, Load More, & Lazy Load | 4.9 | Medium | 2024-04-09 |
| CVE-2024-1974 | WordPress Plugin HT Mega 安全漏洞 — HT Mega Addons for Elementor – Elementor Widgets & Template Builder | 8.8 | High | 2024-04-09 |
| CVE-2024-31457 | Gin-Vue-Admin 安全漏洞 — gin-vue-admin | 7.7 | High | 2024-04-09 |
| CVE-2024-31487 | Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox | 5.8 | Medium | 2024-04-09 |
| CVE-2023-47541 | Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox | 6.5 | Medium | 2024-04-09 |
| CVE-2024-23671 | Fortinet FortiSandbox 路径遍历漏洞 — FortiSandbox | 7.9 | High | 2024-04-09 |
| CVE-2024-2224 | Bitdefender GravityZone Update Server 路径遍历漏洞 — GravityZone Control Center (On Premises) | 8.1 | High | 2024-04-09 |
| CVE-2024-31860 | Apache Zeppelin 输入验证错误漏洞 — Apache Zeppelin | 6.5AI | MediumAI | 2024-04-09 |
| CVE-2024-31978 | Siemens SINEC NMS 路径遍历漏洞 — SINEC NMS | 7.6 | High | 2024-04-09 |
| CVE-2023-52544 | Huawei HarmonyOS 安全漏洞 — HarmonyOS | 7.5AI | HighAI | 2024-04-08 |
| CVE-2024-30417 | Huawei HarmonyOS 安全漏洞 — HarmonyOS | 6.5AI | MediumAI | 2024-04-07 |
| CVE-2024-0406 | archiver 路径遍历漏洞 | 6.1 | Medium | 2024-04-06 |
| CVE-2024-22328 | IBM Maximo Application Suite 安全漏洞 — Maximo Application Suite | 7.5 | High | 2024-04-06 |
| CVE-2024-31851 | CData Sync 安全漏洞 — Sync | 8.6 | High | 2024-04-05 |
| CVE-2024-31850 | CData Arc 安全漏洞 — Arc | 8.6 | High | 2024-04-05 |
| CVE-2024-31849 | CData Connect 安全漏洞 — Connect | 9.8 | Critical | 2024-04-05 |
| CVE-2024-31848 | CData API Server 安全漏洞 — API Server | 9.8 | Critical | 2024-04-05 |
| CVE-2024-31220 | Sunshine 安全漏洞 — Sunshine | 7.3 | High | 2024-04-05 |
| CVE-2024-3311 | Dreamer CMS 路径遍历漏洞 — CMS | 6.3 | Medium | 2024-04-04 |
| CVE-2024-30270 | mailcow 安全漏洞 — mailcow-dockerized | 6.2 | Medium | 2024-04-04 |
| CVE-2024-30254 | MesonLSP 安全漏洞 — mesonlsp | 5.8 | Medium | 2024-04-04 |
| CVE-2024-25693 | Esri Portal For ArcGIS 路径遍历漏洞 — Portal for ArcGIS | 9.9 | Critical | 2024-04-04 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3710 条 CVE 漏洞。