CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3683 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-48381 | Softnext Technologies Mail SQR Expert 安全漏洞 — Mail SQR Expert | 6.5 | Medium | 2023-12-15 |
| CVE-2023-48378 | Softnext Technologies Mail SQR Expert 路径遍历漏洞 — Mail SQR Expert | 7.5 | High | 2023-12-15 |
| CVE-2023-48373 | ITPison OMICARD EDM 路径遍历漏洞 — OMICARD EDM 's SMS | 7.5 | High | 2023-12-15 |
| CVE-2023-49294 | Asterisk 路径遍历漏洞 — asterisk | 4.9 | Medium | 2023-12-14 |
| CVE-2023-48660 | Dell Virtual Appliance Manager 安全漏洞 — vApp Manger | 7.5 | High | 2023-12-14 |
| CVE-2023-44278 | Dell PowerProtect Data Domain 安全漏洞 — PowerProtect DD | 6.7 | Medium | 2023-12-14 |
| CVE-2023-6407 | Schneider Electric Easy UPS Online Monitoring Software 路径遍历漏洞 — Easy UPS Online Monitoring Software | 5.3 | Medium | 2023-12-14 |
| CVE-2023-47624 | Audiobookshelf 路径遍历漏洞 — audiobookshelf | 7.5 | High | 2023-12-13 |
| CVE-2023-44251 | Fortinet FortiWAN 安全漏洞 — FortiWAN | 8.1 | High | 2023-12-13 |
| CVE-2023-6753 | Mlflow 路径遍历漏洞 — mlflow/mlflow | 8.1AI | HighAI | 2023-12-13 |
| CVE-2023-49089 | Umbraco 安全漏洞 — Umbraco-CMS | 7.7 | High | 2023-12-12 |
| CVE-2023-49058 | SAP Master Data Governance 路径遍历漏洞 — SAP Master Data Governance | 3.5 | Low | 2023-12-12 |
| CVE-2023-6120 | WordPress Plugin Welcart e-Commerce 安全漏洞 — Welcart e-Commerce | 4.1 | Medium | 2023-12-09 |
| CVE-2023-6577 | Beijing Baichuo PatrolFlow 2530Pro 安全漏洞 — PatrolFlow 2530Pro | 4.3 | Medium | 2023-12-07 |
| CVE-2023-44306 | Dell DM5500 路径遍历漏洞 — Dell PowerProtect Data Manager DM5500 Appliance | 6.5 | Medium | 2023-12-04 |
| CVE-2023-47279 | Delta Electronics InfraSuite Device Master 安全漏洞 — InfraSuite Device Master | 7.5 | High | 2023-11-30 |
| CVE-2023-49735 | Apache Tiles 输入验证错误漏洞 — Apache Tiles | 10.0 | - | 2023-11-30 |
| CVE-2023-6352 | Aquaforest TIFF Server 安全漏洞 — TIFF Server | 5.3 | Medium | 2023-11-30 |
| CVE-2023-6026 | PHPMemcachedAdmin 路径遍历漏洞 — PHPMemcachedAdmin | 9.8 | Critical | 2023-11-30 |
| CVE-2023-3533 | Chamilo LMS 安全漏洞 — Chamilo | 9.8 | Critical | 2023-11-28 |
| CVE-2022-41951 | OroPlatform 路径遍历漏洞 — platform | 8.6 | High | 2023-11-27 |
| CVE-2023-42000 | Arcserve Unified Data Protection 安全漏洞 — Arcserve UDP | 9.8 | Critical | 2023-11-27 |
| CVE-2023-5607 | Trellix Application and Change Control 路径遍历漏洞 — Trellix Application and Change Control (TACC) | 8.4 | High | 2023-11-27 |
| CVE-2023-4593 | BVRP Software Avanquest Software SLmail 路径遍历漏洞 — SLmail | 6.5 | Medium | 2023-11-23 |
| CVE-2023-6265 | DrayTek Vigor2960 安全漏洞 — Vigor2960 | 6.5 | Medium | 2023-11-22 |
| CVE-2023-6160 | WordPress Plugin LifterLMS 安全漏洞 — LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes | 3.3 | Low | 2023-11-22 |
| CVE-2021-22151 | Elastic Kibana 安全漏洞 — Kibana | 3.1 | Low | 2023-11-22 |
| CVE-2023-48299 | PyTorch 安全漏洞 — serve | 5.3 | Medium | 2023-11-21 |
| CVE-2023-22273 | Adobe RoboHelp 安全漏洞 — RoboHelp | 7.2 | High | 2023-11-17 |
| CVE-2023-6015 | Mlflow 安全漏洞 — mlflow/mlflow | 9.8 | - | 2023-11-16 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3683 条 CVE 漏洞。