CWE-23 相对路径遍历 类弱点 407 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-23 相对路径遍历漏洞源于软件未正确过滤外部输入中的“..”序列,导致构造的文件路径突破受限目录边界。攻击者通常利用此缺陷读取或修改系统敏感文件,获取未授权访问权限。开发者应避免直接使用用户输入拼接路径,需通过白名单验证、规范化路径或限制访问范围来彻底中和危险字符,从而防止路径逃逸。
http://example.com/get-files.jsp?file=report.pdf http://example.com/get-page.php?home=aaa.html http://example.com/some-page.asp?page=index.htmlhttp://example.com/get-files?file=../../../../somedir/somefile http://example.com/../../../../etc/shadow http://example.com/get-files?file=../../../../etc/passwdmy $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwd| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-7146 | Jhenggao iPublish System 安全漏洞 — iPublish System | 7.5 | High | 2025-07-08 |
| CVE-2025-52207 | MIKO MikoPBX 安全漏洞 — MikoPBX | 9.9 | Critical | 2025-06-27 |
| CVE-2025-52922 | InnoShop 安全漏洞 — InnoShop | 7.4 | High | 2025-06-23 |
| CVE-2025-34510 | Sitecore多款产品 安全漏洞 — Experience Manager | 8.8 | High | 2025-06-17 |
| CVE-2025-33112 | IBM AIX和IBM VIOS 安全漏洞 — AIX | 8.4 | High | 2025-06-10 |
| CVE-2025-3365 | B. Braun onlinesuite 安全漏洞 — OnlineSuite | 9.8 | Critical | 2025-06-06 |
| CVE-2025-49466 | aerc 安全漏洞 — aerc | 5.8 | Medium | 2025-06-05 |
| CVE-2025-48957 | AstrBot 安全漏洞 — AstrBot | 7.5 | High | 2025-06-02 |
| CVE-2025-47445 | WordPress plugin Eventin 安全漏洞 — Eventin | 7.5 | High | 2025-05-14 |
| CVE-2025-22859 | Fortinet FortiClientEMS 安全漏洞 — FortiClientEMS | 5.0 | Medium | 2025-05-13 |
| CVE-2025-24350 | Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Device Admin | 7.1 | High | 2025-04-30 |
| CVE-2025-24343 | Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Solutions | 5.4 | Medium | 2025-04-30 |
| CVE-2023-35816 | DevExpress 安全漏洞 — DevExpress | 3.5 | Low | 2025-04-28 |
| CVE-2025-46433 | JetBrains TeamCity 安全漏洞 — TeamCity | 4.9 | Medium | 2025-04-25 |
| CVE-2025-43016 | JetBrains Rider 安全漏洞 — Rider | 5.4 | Medium | 2025-04-25 |
| CVE-2025-27791 | Collabora Online 安全漏洞 — online | 6.8AI | MediumAI | 2025-04-15 |
| CVE-2025-32017 | Umbraco 安全漏洞 — Umbraco-CMS | 8.8 | High | 2025-04-08 |
| CVE-2025-32409 | Ratta SuperNote A6 X2 Nomad 安全漏洞 — SuperNote A6 X2 Nomad | 8.1 | High | 2025-04-07 |
| CVE-2025-32137 | WordPress plugin s2Member 安全漏洞 — s2Member | 4.9 | Medium | 2025-04-04 |
| CVE-2023-40714 | Fortinet FortiSIEM 安全漏洞 — FortiSIEM | 9.7 | Critical | 2025-04-02 |
| CVE-2025-2007 | WordPress plugin Import Export Suite for CSV and XML Datafeed 安全漏洞 — WP Ultimate CSV Importer – Import CSV, XML & Excel into WordPress | 8.1 | High | 2025-04-01 |
| CVE-2025-29789 | OpenEMR 安全漏洞 — openemr | 6.5AI | MediumAI | 2025-03-25 |
| CVE-2025-27553 | Apache Commons VFS 安全漏洞 — Apache Commons VFS | - | - | 2025-03-23 |
| CVE-2024-6583 | Quivr 安全漏洞 — stangirard/quivr | 7.5 | - | 2025-03-20 |
| CVE-2024-8551 | AgentScope 安全漏洞 — modelscope/agentscope | 9.8 | - | 2025-03-20 |
| CVE-2024-10513 | AnythingLLM 安全漏洞 — mintplex-labs/anything-llm | 7.2 | - | 2025-03-20 |
| CVE-2024-7058 | Open WebUI 安全漏洞 — parisneo/lollms | 6.5 | - | 2025-03-20 |
| CVE-2024-6483 | Aim 安全漏洞 — aimhubio/aim | 9.1 | - | 2025-03-20 |
| CVE-2024-9363 | polyaxon 安全漏洞 — polyaxon/polyaxon | 7.5 | - | 2025-03-20 |
| CVE-2024-12019 | LogicalDOC 安全漏洞 — LogicalDOC Community | 6.5 | - | 2025-03-14 |
CWE-23(相对路径遍历) 是常见的弱点类别,本平台收录该类弱点关联的 407 条 CVE 漏洞。