CWE-36 绝对路径遍历 类弱点 112 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-36绝对路径遍历属于文件访问控制漏洞。当软件利用外部输入构建受限目录内的文件路径时,若未正确过滤绝对路径序列(如“/abs/path”),攻击者即可绕过限制,访问受限目录外的敏感文件或系统资源。开发者应严格验证输入,禁止使用绝对路径,并采用白名单机制或规范化路径处理,确保最终解析路径始终位于预期的安全沙箱内。
String filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);import os import sys def main(): filename = sys.argv[1] path = os.path.join(os.getcwd(), filename) try: with open(path, 'r') as f: file_data = f.read() except FileNotFoundError as e: print("Error - file not found") main()import os import sys def main(): filename = sys.argv[1] path = os.path.normpath(f"{os.getcwd()}{os.sep}{filename}") if path.startswith("/home/cwe/documents/"): try: with open(path, 'r') as f: file_data = f.read() except FileNotFoundError as e: print("Error - file not found") main()| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-53698 | Silverpeas 安全漏洞 — Silverpeas | 6.5 | Medium | 2026-06-10 |
| CVE-2026-10075 | Interinfo DreamMaker 安全漏洞 — DreamMaker | 5.3 | Medium | 2026-05-29 |
| CVE-2026-10044 | ai-goofish-monitor 安全漏洞 — ai-goofish-monitor | 7.5 | High | 2026-05-28 |
| CVE-2026-32997 | Veeam Backup And Replication 安全漏洞 — Backup and Replication | - | - | 2026-05-28 |
| CVE-2026-4782 | WordPress plugin Avada Builder 安全漏洞 — Avada (Fusion) Builder | 6.5 | Medium | 2026-05-13 |
| CVE-2026-32175 | Microsoft .NET 安全漏洞 — .NET 10.0 | 4.3 | Medium | 2026-05-12 |
| CVE-2026-6418 | PaperCut MF 安全漏洞 — PaperCut NG/MF | 2.7 | - | 2026-05-05 |
| CVE-2026-44029 | Nix 安全漏洞 — Nix | 5.3 | Medium | 2026-05-05 |
| CVE-2026-7217 | PromptX 路径遍历漏洞 — PromptX | 5.3 | Medium | 2026-04-28 |
| CVE-2026-34515 | aiohttp 代码问题漏洞 — aiohttp | 5.3 | - | 2026-04-01 |
| CVE-2026-4373 | WordPress plugin JetFormBuilder 安全漏洞 — JetFormBuilder — Dynamic Blocks Form Builder | 7.5 | High | 2026-03-21 |
| CVE-2026-0846 | NLTK 安全漏洞 — nltk/nltk | 7.5 | - | 2026-03-09 |
| CVE-2026-2753 | Navtor NavBox 安全漏洞 — NavBox | 7.5 | High | 2026-03-06 |
| CVE-2026-28414 | Gradio 安全漏洞 — gradio | 7.5 | High | 2026-02-27 |
| CVE-2026-26337 | Hyland Alfresco Transformation Service 安全漏洞 — Alfresco Transformation Service (Enterprise) | 8.2 | High | 2026-02-19 |
| CVE-2026-1330 | HAMASTAR MeetingHub 安全漏洞 — MeetingHub | 7.5 | High | 2026-01-22 |
| CVE-2026-1020 | Code-Projects Police Station Management System 安全漏洞 — Police Statistics Database System | 5.3 | Medium | 2026-01-16 |
| CVE-2026-1018 | Code-Projects Police Station Management System 安全漏洞 — Police Statistics Database System | 7.5 | High | 2026-01-16 |
| CVE-2026-20834 | Microsoft Windows Shell 安全漏洞 — Windows 10 Version 1607 | 4.6 | Medium | 2026-01-13 |
| CVE-2025-15237 | Quanta QOCA aim AI Medical Cloud Platform 安全漏洞 — QOCA aim AI Medical Cloud Platform | 4.3 | Medium | 2026-01-05 |
| CVE-2025-15236 | Quanta QOCA aim AI Medical Cloud Platform 安全漏洞 — QOCA aim AI Medical Cloud Platform | 4.3 | Medium | 2026-01-05 |
| CVE-2025-15227 | WELLTEND BPMFlowWebkit 安全漏洞 — BPMFlowWebkit | 7.5 | High | 2025-12-29 |
| CVE-2025-14848 | Advantech WebAccess/SCADA 安全漏洞 — WebAccess/SCADA | 4.3 | Medium | 2025-12-18 |
| CVE-2025-67898 | Mailjet MJML 安全漏洞 — MJML | 4.5 | Medium | 2025-12-14 |
| CVE-2025-34392 | Barracuda Service Center 安全漏洞 — RMM | 9.8AI | CriticalAI | 2025-12-10 |
| CVE-2025-14253 | Galaxy Software Services Vitals ESP 安全漏洞 — Vitals ESP | 4.9 | Medium | 2025-12-08 |
| CVE-2025-36357 | AMD Store Queue 安全漏洞 — IBM Planning Analytics Local | 8.0 | High | 2025-11-17 |
| CVE-2025-7846 | WordPress plugin User Extra Fields 安全漏洞 — WordPress User Extra Fields | 8.8 | High | 2025-10-31 |
| CVE-2025-8575 | WordPress plugin LWS Cleaner 安全漏洞 — LWS Cleaner | 7.2 | High | 2025-09-12 |
| CVE-2025-9516 | WordPress plugin atec Debug 安全漏洞 — atec Debug | 4.9 | Medium | 2025-09-04 |
CWE-36(绝对路径遍历) 是常见的弱点类别,本平台收录该类弱点关联的 112 条 CVE 漏洞。