CWE-427 对搜索路径元素未加控制 类弱点 556 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-427 属于路径遍历类漏洞,指程序在搜索资源时,其路径中包含可由攻击者控制的目录。攻击者通常通过在该目录下放置恶意文件或库,诱导程序加载并执行,从而劫持系统控制权。开发者应避免使用相对路径或不可信的环境变量,转而采用绝对路径,并严格限制相关目录的写入权限,以确保资源加载的安全性。
... System.Runtime.getRuntime().exec("make"); ...func ExecuteGitCommand(name string, arg []string) error { c := exec.Command(name, arg...) var err error c.Path, err = exec.LookPath(name) if err != nil { return err } }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-44358 | Espressif Shared GitHub DangerJS 安全漏洞 — shared-github-dangerjs | 8.2 | High | 2026-05-28 |
| CVE-2026-47274 | pam_usb 代码问题漏洞 — pam_usb | 6.3 | Medium | 2026-05-27 |
| CVE-2023-52945 | Synology BeeDrive 代码问题漏洞 — BeeDrive for desktop | 7.8 | High | 2026-05-27 |
| CVE-2025-41670 | Phoenix Contact多款产品 代码问题漏洞 — AXC F 1152 | 7.8 | High | 2026-05-27 |
| CVE-2025-14575 | Qt 代码问题漏洞 — Qt | - | - | 2026-05-19 |
| CVE-2026-32323 | Mullvad VPN desktop and mobile app 安全漏洞 — mullvadvpn-app | 7.3 | High | 2026-05-19 |
| CVE-2026-47092 | Claude HUD 代码问题漏洞 — claude-hud | 7.8 | High | 2026-05-18 |
| CVE-2025-62628 | AMD AIM-T Manageability Service 代码问题漏洞 — AIM-T Manageability Service | - | - | 2026-05-14 |
| CVE-2024-47091 | Checkmk 代码问题漏洞 — Checkmk | - | - | 2026-05-13 |
| CVE-2026-44612 | Bytello Share 代码问题漏洞 — Bytello Share (Windows Edition) installer executable | - | - | 2026-05-13 |
| CVE-2026-45004 | OpenClaw 代码问题漏洞 — OpenClaw | 7.8 | High | 2026-05-11 |
| CVE-2026-44406 | ZTE Cloud PC client uSmartView 代码问题漏洞 — ZXCLOUD iRAI | 5.7 | Medium | 2026-05-07 |
| CVE-2026-40004 | ZTE ZXCLOUD iRAI 代码问题漏洞 — ZXCLOUD iRAI | 5.5 | Medium | 2026-05-07 |
| CVE-2026-21661 | Johnson Controls AC2000 代码问题漏洞 — AC2000 | 6.6AI | MediumAI | 2026-05-06 |
| CVE-2026-6788 | WatchGuard Agent 代码问题漏洞 — WatchGuard Agent | 7.3AI | HighAI | 2026-05-06 |
| CVE-2026-25852 | Acronis DeviceLock DLP 代码问题漏洞 — Acronis DeviceLock DLP | 7.8AI | HighAI | 2026-04-29 |
| CVE-2026-41373 | OpenClaw 代码问题漏洞 — OpenClaw | 6.1 | Medium | 2026-04-28 |
| CVE-2026-7279 | eMPIA AVACAST 代码问题漏洞 — AVACAST | 7.8 | High | 2026-04-28 |
| CVE-2026-42171 | NSIS 代码问题漏洞 — Nullsoft Scriptable Install System | 7.8 | High | 2026-04-24 |
| CVE-2026-32172 | Microsoft Power Apps 代码问题漏洞 — Microsoft Power Apps | 8.0 | High | 2026-04-23 |
| CVE-2025-10549 | EfficientLab Controlio 代码问题漏洞 — Controlio | 7.3AI | HighAI | 2026-04-23 |
| CVE-2026-34488 | i-PRO IP Setting Software 代码问题漏洞 — IP Setting Software | 7.8AI | HighAI | 2026-04-23 |
| CVE-2026-32679 | Japan Media Systems LiveOn Meet Client和Canon Network Camera Plugin 代码问题漏洞 — Downloader5Installer.exe | 7.8AI | HighAI | 2026-04-23 |
| CVE-2026-6421 | Mobatek MobaXterm 安全漏洞 — MobaXterm Home Edition | 7.0 | High | 2026-04-17 |
| CVE-2026-34632 | Adobe Photoshop Installer 安全漏洞 — Adobe Photoshop Installer | 8.2 | High | 2026-04-15 |
| CVE-2026-4134 | Lenovo Software Fix 安全漏洞 — Software Fix | 7.3 | High | 2026-04-15 |
| CVE-2026-1636 | Lenovo Service Bridge 安全漏洞 — Service Bridge | 6.7 | Medium | 2026-04-15 |
| CVE-2026-5397 | OMRON PowerAttendant 安全漏洞 — PowerAttendant Standard Edition | 7.8 | High | 2026-04-15 |
| CVE-2026-4158 | KeePassXC 代码问题漏洞 — KeePassXC | 7.3AI | HighAI | 2026-04-11 |
| CVE-2026-5055 | NoMachine 代码问题漏洞 — NoMachine | 7.8AI | HighAI | 2026-04-11 |
CWE-427(对搜索路径元素未加控制) 是常见的弱点类别,本平台收录该类弱点关联的 556 条 CVE 漏洞。