CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3683 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-5245 | MLeap 安全漏洞 | 7.5 | High | 2023-11-15 |
| CVE-2023-6032 | Schneider Electric Galaxy VS和Schneider Electric Galaxy VL 安全漏洞 — Galaxy VS | 5.3 | Medium | 2023-11-15 |
| CVE-2023-40055 | SolarWinds Network Configuration Manager 安全漏洞 — Network Configuration Manager | 8.0 | High | 2023-11-09 |
| CVE-2023-40054 | SolarWinds Network Configuration Manager 安全漏洞 — Network Configuration Manager | 8.0 | High | 2023-11-09 |
| CVE-2023-46253 | squidex 路径遍历漏洞 — squidex | 9.1 | Critical | 2023-11-07 |
| CVE-2023-39299 | QNAP Systems Music Station 路径遍历漏洞 — Music Station | 7.5 | High | 2023-11-03 |
| CVE-2023-3961 | Samba 安全漏洞 — Red Hat Enterprise Linux 8 | 9.1 | Critical | 2023-11-03 |
| CVE-2023-41356 | WisdomGarden Tronclass ilearn 安全漏洞 — Tronclass ilearn | 6.5 | Medium | 2023-11-03 |
| CVE-2023-41344 | NCSIST ManageEngine Mobile Device Manager 安全漏洞 — MDM | 7.5 | High | 2023-11-03 |
| CVE-2023-20220 | Cisco Firepower Management Center 安全漏洞 — Cisco Firepower Management Center | 7.2 | High | 2023-11-01 |
| CVE-2023-33227 | SolarWinds Network Configuration Manager 路径遍历漏洞 — Network Configuration Manager | 8.0 | High | 2023-11-01 |
| CVE-2023-33226 | SolarWinds Network Configuration Manager 路径遍历漏洞 — Network Configuration Manager | 8.0 | High | 2023-11-01 |
| CVE-2023-2621 | Hitachi Energy MACH System Software 路径遍历漏洞 — MACH System Software | 6.5 | Medium | 2023-11-01 |
| CVE-2023-46237 | FOGProject 路径遍历漏洞 — fogproject | 5.8 | Medium | 2023-10-31 |
| CVE-2023-43648 | baserCMS 路径遍历漏洞 — basercms | 4.9 | Medium | 2023-10-30 |
| CVE-2023-42804 | BigBlueButton 路径遍历漏洞 — bigbluebutton | 3.1 | Low | 2023-10-30 |
| CVE-2005-10002 | WordPress Plugin almosteffortless secure-files 路径遍历漏洞 — secure-files Plugin | 5.5 | Medium | 2023-10-29 |
| CVE-2023-30967 | Palantir Gotham Orbital-Simulator 路径遍历漏洞 — com.palantir.meta:orbital-simulator | 9.8 | Critical | 2023-10-25 |
| CVE-2023-42488 | Alexander Maier EisBaer Scada 路径遍历漏洞 — v3.0.6433.1964 | 7.5 | High | 2023-10-25 |
| CVE-2023-26578 | IDAttend IDWeb 代码问题漏洞 — IDWeb | 8.8 | High | 2023-10-25 |
| CVE-2023-46122 | sbt 路径遍历漏洞 — sbt | 3.9 | Low | 2023-10-23 |
| CVE-2023-44256 | Fortinet FortiAnalyzer 代码问题漏洞 — FortiAnalyzer | 6.4 | Medium | 2023-10-20 |
| CVE-2023-5414 | WordPress Plugin Icegram Express 路径遍历漏洞 — Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress | 9.1 | Critical | 2023-10-20 |
| CVE-2023-45823 | Artifact Hub 路径遍历漏洞 — hub | 7.5 | High | 2023-10-19 |
| CVE-2023-35187 | SolarWinds Access Rights Manager 路径遍历漏洞 — Access Rights Manager | 8.8 | High | 2023-10-19 |
| CVE-2023-35185 | SolarWinds Access Rights Manager 路径遍历漏洞 — Access Rights Manager | 6.8 | Medium | 2023-10-19 |
| CVE-2023-5212 | WordPress plugin AI ChatBot 路径遍历漏洞 — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | 9.6 | Critical | 2023-10-19 |
| CVE-2023-5241 | WordPress plugin AI ChatBot 路径遍历漏洞 — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | 9.6 | Critical | 2023-10-19 |
| CVE-2023-43801 | Arduino 路径遍历漏洞 — arduino-create-agent | 6.1 | Medium | 2023-10-18 |
| CVE-2023-43802 | Arduino 路径遍历漏洞 — arduino-create-agent | 7.1 | High | 2023-10-18 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3683 条 CVE 漏洞。