CWE-35: CWE-35

62
Total CVEs
5
Critical
34
High
7.0
Avg CVSS

Yearly Trend

2026
6
2025
38
2024
14
2023
3
2020
1

Top Affected Vendors

1 Q Free 5
2 Splunk 3
3 Broadcom 2
4 Axis 2
5 Wpjobportal 1
6 Nlnetlabs 1
7 Microsoft 1
8 Agnai 1
9 Dell 1
10 Parall 1

All CWE-35 CVEs (62)

CVE-2025-39467
9.8

This CVE describes a path traversal vulnerability in the Mikado-Themes Wanderland WordPress theme that allows attackers to perform local file inclusio...

Nov 6, 2025
CVE-2025-41723
9.8

CVE-2025-41723 is a critical directory traversal vulnerability in the importFile SOAP method that allows unauthenticated remote attackers to bypass pa...

Oct 22, 2025
CVE-2025-30515
9.8

CVE-2025-30515 is a path traversal vulnerability in CyberData 011209 Intercom systems that allows authenticated attackers to upload arbitrary files to...

Jun 9, 2025
CVE-2023-39916
9.3

This vulnerability in Routinator allows attackers to write files outside the intended directory when the optional keep-rrdp-responses feature is enabl...

Sep 13, 2023
CVE-2020-27130
9.1

CVE-2020-27130 is a path traversal vulnerability in Cisco Security Manager that allows unauthenticated remote attackers to download arbitrary files fr...

Nov 17, 2020
CVE-2025-41736
8.8

A path traversal vulnerability in PHP allows low-privileged remote attackers to upload or overwrite Python scripts, leading to remote code execution. ...

Nov 18, 2025
CVE-2024-49249
8.6

This path traversal vulnerability in SMSA Express SMSA Shipping WordPress plugin allows attackers to delete arbitrary files on the server. It affects ...

Jan 7, 2025
CVE-2024-21575
8.6

ComfyUI-Impact-Pack extension for ComfyUI has a path traversal vulnerability in the /upload/temp endpoint that allows attackers to write arbitrary fil...

Dec 12, 2024
CVE-2024-52447
8.6

This path traversal vulnerability in the WordPress 'Contact Page With Google Map' plugin allows attackers to delete arbitrary files on the server usin...

Nov 20, 2024
CVE-2024-56214
8.3

This path traversal vulnerability in the Userpro WordPress plugin allows attackers to access arbitrary files on the server by manipulating file paths....

Dec 31, 2024
CVE-2025-48090
8.2

This vulnerability allows attackers to perform path traversal attacks using '.../...//' sequences to include arbitrary PHP files on the server. It aff...

Nov 6, 2025
CVE-2025-52810
8.1

This CVE describes a path traversal vulnerability in the Katerio - Magazine WordPress theme that allows attackers to perform PHP local file inclusion....

Jun 27, 2025
CVE-2025-39491
8.1

CVE-2025-39491 is a path traversal vulnerability in the WHMPress WordPress plugin that allows attackers to read arbitrary files on the server. This af...

May 16, 2025
CVE-2025-39470
8.1

This path traversal vulnerability in the Ivy School WordPress theme allows attackers to include local PHP files using '.../...//' sequences. It enable...

Apr 18, 2025
CVE-2024-54362
8.1

This path traversal vulnerability in the GetShop eCommerce WordPress plugin allows attackers to access files outside the intended directory. It affect...

Mar 28, 2025
CVE-2024-41973
8.1

This vulnerability allows a low-privileged remote attacker to write arbitrary files to the filesystem, potentially leading to root privilege escalatio...

Nov 18, 2024
CVE-2023-32714
8.1

CVE-2023-32714 is a path traversal vulnerability in Splunk App for Lookup File Editing that allows low-privileged users to read and write files in res...

Jun 1, 2023
CVE-2025-47176
7.8

This vulnerability in Microsoft Office Outlook allows an authorized attacker to execute arbitrary code on the local system through a path traversal is...

Jun 10, 2025
CVE-2025-30014
7.7

SAP Capital Yield Tax Management contains a directory traversal vulnerability (CWE-35) that allows attackers with low-privileged access to read files ...

Apr 8, 2025
CVE-2025-67914
7.5

This path traversal vulnerability in the VidMov WordPress theme allows attackers to access files outside the intended directory using '.../...//' sequ...

Jan 8, 2026
CVE-2025-68428
7.5

CVE-2025-68428 is a path traversal vulnerability in jsPDF's Node.js builds that allows attackers to read arbitrary local files when user-controlled in...

Jan 5, 2026
CVE-2025-48317
7.5

This path traversal vulnerability in the WooCommerce Payment Gateway for Saferpay plugin allows attackers to access files outside the intended directo...

Sep 5, 2025
CVE-2025-52805
7.5

This CVE describes a Path Traversal vulnerability in the VaultDweller Leyka WordPress plugin that allows PHP Local File Inclusion (LFI). Attackers can...

Jul 4, 2025
CVE-2025-49451
7.5

A path traversal vulnerability in the Aeroscroll Gallery WordPress plugin allows attackers to access files outside the intended directory. This affect...

Jun 17, 2025
CVE-2025-47636
7.5

This CVE describes a path traversal vulnerability in the WordPress List Category Posts plugin that allows attackers to perform local file inclusion (L...

May 7, 2025
CVE-2025-32585
7.5

This CVE describes a path traversal vulnerability in the Trusty Plugins Shop Products Filter WordPress plugin that allows attackers to perform local f...

Apr 11, 2025
CVE-2025-30834
7.5

A path traversal vulnerability in the Bit Assist WordPress plugin allows attackers to access files outside the intended directory by manipulating file...

Apr 1, 2025
CVE-2025-26935
7.5

This CVE describes a path traversal vulnerability in the WP Job Portal WordPress plugin that allows attackers to perform local file inclusion (LFI) at...

Feb 25, 2025
CVE-2024-52498
7.5

This CVE describes a path traversal vulnerability in Softpulse Infotech's SP Blog Designer WordPress plugin that allows attackers to include arbitrary...

Nov 28, 2024
CVE-2024-50054
7.5

CVE-2024-50054 is a path traversal vulnerability in back-end systems that allows attackers to read arbitrary files from the file system by manipulatin...

Nov 22, 2024
CVE-2024-51582
7.5

This path traversal vulnerability in the ThimPress WP Hotel Booking WordPress plugin allows attackers to include local PHP files using '.../...//' seq...

Nov 4, 2024
CVE-2024-45248
7.5

This CVE describes a path traversal vulnerability (CWE-35) in Multi-DNC software that allows attackers to access files outside the intended directory ...

Oct 6, 2024
CVE-2024-0113
7.5

This vulnerability allows attackers to perform path traversal attacks via specially crafted URIs in NVIDIA networking products' web interfaces. Succes...

Aug 12, 2024
CVE-2024-36991
7.5

This vulnerability allows attackers to perform path traversal attacks on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This could ...

Jul 1, 2024
CVE-2023-7263
7.3

This path traversal vulnerability in Huawei home music systems allows attackers to delete or modify files by manipulating file paths. It affects users...

Dec 28, 2024
CVE-2025-58972
7.2

This path traversal vulnerability in the Barcode Scanner with Inventory & Order Manager WordPress plugin allows attackers to access files outside the ...

Nov 6, 2025
CVE-2025-26356
7.2

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to overwrite sensitive files by manipulating file paths in H...

Feb 12, 2025
CVE-2025-26354
7.2

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to overwrite sensitive files by manipulating file paths in H...

Feb 12, 2025
CVE-2023-21417
7.1

This CVE describes a path traversal vulnerability in Axis camera systems' VAPIX API manageoverlayimage.cgi endpoint that allows authenticated users wi...

Nov 21, 2023
CVE-2025-24908
6.8

This path traversal vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to access files outside restricted director...

Apr 16, 2025
CVE-2025-28973
6.5

This path traversal vulnerability in the AA-Team Pro Bulk Watermark WordPress plugin allows attackers to access files outside the intended directory u...

Dec 31, 2025
CVE-2025-43907
6.5

This CVE describes a path traversal vulnerability in Dell PowerProtect Data Domain systems where attackers can use '.../...//' sequences to access una...

Oct 7, 2025
CVE-2025-53561
6.5

A path traversal vulnerability in the miniOrange Prevent files/folders access WordPress plugin allows attackers to bypass file access restrictions and...

Aug 20, 2025
CVE-2025-26352
6.5

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to delete sensitive files by manipulating HTTP requests. It ...

Feb 12, 2025
CVE-2025-26355
6.5

This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to delete sensitive files via crafted HTTP requests. It affe...

Feb 12, 2025
CVE-2024-56213
6.5

This path traversal vulnerability in the Eventin WordPress plugin allows attackers to access files outside the intended directory using '.../...//' se...

Dec 31, 2024
CVE-2025-46256
6.4

This path traversal vulnerability in Advanced Database Cleaner PRO WordPress plugin allows attackers to access files outside the intended directory us...

Jan 7, 2026
CVE-2025-5454
6.4

This CVE describes a path traversal vulnerability in Axis ACAP configuration files that could allow privilege escalation. It affects Axis devices conf...

Nov 11, 2025
CVE-2025-20320
6.3

A path traversal vulnerability in Splunk Enterprise and Cloud Platform allows low-privileged users to delete arbitrary files via a malicious payload o...

Jul 7, 2025
CVE-2025-66004
5.7

A path traversal vulnerability in usbmuxd allows local users to escalate privileges to the service user account. This affects systems running vulnerab...

Dec 10, 2025

About CWE-35 (CWE-35)

Our database tracks 62 CVEs classified as CWE-35, with 5 rated critical and 34 rated high severity. The average CVSS score for CWE-35 vulnerabilities is 7.0.

External reference: View CWE-35 on MITRE CWE →

Monitor CWE-35 Vulnerabilities

Get alerted when new CWE-35 CVEs affect your infrastructure.

Start Monitoring Free