CWE-23 相对路径遍历 类弱点 361 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-23 相对路径遍历漏洞源于软件未正确过滤外部输入中的“..”序列,导致构造的文件路径突破受限目录边界。攻击者通常利用此缺陷读取或修改系统敏感文件,获取未授权访问权限。开发者应避免直接使用用户输入拼接路径,需通过白名单验证、规范化路径或限制访问范围来彻底中和危险字符,从而防止路径逃逸。
http://example.com/get-files.jsp?file=report.pdf http://example.com/get-page.php?home=aaa.html http://example.com/some-page.asp?page=index.htmlhttp://example.com/get-files?file=../../../../somedir/somefile http://example.com/../../../../etc/shadow http://example.com/get-files?file=../../../../etc/passwdmy $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwd| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2025-9570 | Sunnet eHRD CTMS 安全漏洞 — eHRD CTMS | 4.9 | Medium | 2025-09-01 |
| CVE-2025-55202 | Opencast 安全漏洞 — opencast | 6.5 | - | 2025-08-29 |
| CVE-2025-9639 | Ai3 QbiCRMGateway 安全漏洞 — QbiCRMGateway | 7.5 | High | 2025-08-29 |
| CVE-2021-4459 | SMA Solar Technology AG Sunny Boy 安全漏洞 — Boy 3.0 | 6.5 | Medium | 2025-08-27 |
| CVE-2025-8464 | WordPress plugin Drag and Drop Multiple File Upload for Contact Form 安全漏洞 — Drag and Drop Multiple File Upload for Contact Form 7 | 5.3 | Medium | 2025-08-16 |
| CVE-2024-48892 | Fortinet FortiSOAR 安全漏洞 — FortiSOAR | 6.4 | Medium | 2025-08-12 |
| CVE-2024-40588 | Fortinet多款产品 安全漏洞 — FortiCamera | 4.2 | Medium | 2025-08-12 |
| CVE-2025-53779 | Microsoft Windows Kerberos 安全漏洞 — Windows Server 2025 | 7.2 | High | 2025-08-12 |
| CVE-2025-55013 | Assemblyline 4 Service Client 安全漏洞 — assemblyline | 4.2 | Medium | 2025-08-09 |
| CVE-2025-53082 | SAMSUNG DMS 安全漏洞 — Data Management Server | 6.1 | Medium | 2025-07-29 |
| CVE-2025-54531 | JetBrains TeamCity 安全漏洞 — TeamCity | 7.7 | High | 2025-07-28 |
| CVE-2025-54317 | Logpoint 安全漏洞 — Logpoint | 8.4 | High | 2025-07-20 |
| CVE-2025-7619 | WellChoose BatchSignCS 安全漏洞 — BatchSignCS | 8.8 | High | 2025-07-14 |
| CVE-2025-48817 | Microsoft Remote Desktop Client 安全漏洞 — Remote Desktop client for Windows Desktop | 8.8 | High | 2025-07-08 |
| CVE-2025-7146 | Jhenggao iPublish System 安全漏洞 — iPublish System | 7.5 | High | 2025-07-08 |
| CVE-2025-52207 | MIKO MikoPBX 安全漏洞 — MikoPBX | 9.9 | Critical | 2025-06-27 |
| CVE-2025-52922 | InnoShop 安全漏洞 — InnoShop | 7.4 | High | 2025-06-23 |
| CVE-2025-34510 | Sitecore多款产品 安全漏洞 — Experience Manager | 8.8 | High | 2025-06-17 |
| CVE-2025-33112 | IBM AIX和IBM VIOS 安全漏洞 — AIX | 8.4 | High | 2025-06-10 |
| CVE-2025-3365 | B. Braun onlinesuite 安全漏洞 — OnlineSuite | 9.8 | Critical | 2025-06-06 |
| CVE-2025-49466 | aerc 安全漏洞 — aerc | 5.8 | Medium | 2025-06-05 |
| CVE-2025-48957 | AstrBot 安全漏洞 — AstrBot | 7.5 | High | 2025-06-02 |
| CVE-2025-47445 | WordPress plugin Eventin 安全漏洞 — Eventin | 7.5 | High | 2025-05-14 |
| CVE-2025-22859 | Fortinet FortiClientEMS 安全漏洞 — FortiClientEMS | 5.0 | Medium | 2025-05-13 |
| CVE-2025-24350 | Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Device Admin | 7.1 | High | 2025-04-30 |
| CVE-2025-24343 | Bosch Rexroth ctrlX OS 安全漏洞 — ctrlX OS - Solutions | 5.4 | Medium | 2025-04-30 |
| CVE-2023-35816 | DevExpress 安全漏洞 — DevExpress | 3.5 | Low | 2025-04-28 |
| CVE-2025-46433 | JetBrains TeamCity 安全漏洞 — TeamCity | 4.9 | Medium | 2025-04-25 |
| CVE-2025-43016 | JetBrains Rider 安全漏洞 — Rider | 5.4 | Medium | 2025-04-25 |
| CVE-2025-27791 | Collabora Online 安全漏洞 — online | 6.8AI | MediumAI | 2025-04-15 |
CWE-23(相对路径遍历) 是常见的弱点类别,本平台收录该类弱点关联的 361 条 CVE 漏洞。