CWE-35: CWE-35
Yearly Trend
Top Affected Vendors
All CWE-35 CVEs (62)
This CVE describes a path traversal vulnerability in the Mikado-Themes Wanderland WordPress theme that allows attackers to perform local file inclusio...
Nov 6, 2025CVE-2025-41723 is a critical directory traversal vulnerability in the importFile SOAP method that allows unauthenticated remote attackers to bypass pa...
Oct 22, 2025CVE-2025-30515 is a path traversal vulnerability in CyberData 011209 Intercom systems that allows authenticated attackers to upload arbitrary files to...
Jun 9, 2025This vulnerability in Routinator allows attackers to write files outside the intended directory when the optional keep-rrdp-responses feature is enabl...
Sep 13, 2023CVE-2020-27130 is a path traversal vulnerability in Cisco Security Manager that allows unauthenticated remote attackers to download arbitrary files fr...
Nov 17, 2020A path traversal vulnerability in PHP allows low-privileged remote attackers to upload or overwrite Python scripts, leading to remote code execution. ...
Nov 18, 2025This path traversal vulnerability in SMSA Express SMSA Shipping WordPress plugin allows attackers to delete arbitrary files on the server. It affects ...
Jan 7, 2025ComfyUI-Impact-Pack extension for ComfyUI has a path traversal vulnerability in the /upload/temp endpoint that allows attackers to write arbitrary fil...
Dec 12, 2024This path traversal vulnerability in the WordPress 'Contact Page With Google Map' plugin allows attackers to delete arbitrary files on the server usin...
Nov 20, 2024This path traversal vulnerability in the Userpro WordPress plugin allows attackers to access arbitrary files on the server by manipulating file paths....
Dec 31, 2024This vulnerability allows attackers to perform path traversal attacks using '.../...//' sequences to include arbitrary PHP files on the server. It aff...
Nov 6, 2025This CVE describes a path traversal vulnerability in the Katerio - Magazine WordPress theme that allows attackers to perform PHP local file inclusion....
Jun 27, 2025CVE-2025-39491 is a path traversal vulnerability in the WHMPress WordPress plugin that allows attackers to read arbitrary files on the server. This af...
May 16, 2025This path traversal vulnerability in the Ivy School WordPress theme allows attackers to include local PHP files using '.../...//' sequences. It enable...
Apr 18, 2025This path traversal vulnerability in the GetShop eCommerce WordPress plugin allows attackers to access files outside the intended directory. It affect...
Mar 28, 2025This vulnerability allows a low-privileged remote attacker to write arbitrary files to the filesystem, potentially leading to root privilege escalatio...
Nov 18, 2024CVE-2023-32714 is a path traversal vulnerability in Splunk App for Lookup File Editing that allows low-privileged users to read and write files in res...
Jun 1, 2023This vulnerability in Microsoft Office Outlook allows an authorized attacker to execute arbitrary code on the local system through a path traversal is...
Jun 10, 2025SAP Capital Yield Tax Management contains a directory traversal vulnerability (CWE-35) that allows attackers with low-privileged access to read files ...
Apr 8, 2025This path traversal vulnerability in the VidMov WordPress theme allows attackers to access files outside the intended directory using '.../...//' sequ...
Jan 8, 2026CVE-2025-68428 is a path traversal vulnerability in jsPDF's Node.js builds that allows attackers to read arbitrary local files when user-controlled in...
Jan 5, 2026This path traversal vulnerability in the WooCommerce Payment Gateway for Saferpay plugin allows attackers to access files outside the intended directo...
Sep 5, 2025This CVE describes a Path Traversal vulnerability in the VaultDweller Leyka WordPress plugin that allows PHP Local File Inclusion (LFI). Attackers can...
Jul 4, 2025A path traversal vulnerability in the Aeroscroll Gallery WordPress plugin allows attackers to access files outside the intended directory. This affect...
Jun 17, 2025This CVE describes a path traversal vulnerability in the WordPress List Category Posts plugin that allows attackers to perform local file inclusion (L...
May 7, 2025This CVE describes a path traversal vulnerability in the Trusty Plugins Shop Products Filter WordPress plugin that allows attackers to perform local f...
Apr 11, 2025A path traversal vulnerability in the Bit Assist WordPress plugin allows attackers to access files outside the intended directory by manipulating file...
Apr 1, 2025This CVE describes a path traversal vulnerability in the WP Job Portal WordPress plugin that allows attackers to perform local file inclusion (LFI) at...
Feb 25, 2025This CVE describes a path traversal vulnerability in Softpulse Infotech's SP Blog Designer WordPress plugin that allows attackers to include arbitrary...
Nov 28, 2024CVE-2024-50054 is a path traversal vulnerability in back-end systems that allows attackers to read arbitrary files from the file system by manipulatin...
Nov 22, 2024This path traversal vulnerability in the ThimPress WP Hotel Booking WordPress plugin allows attackers to include local PHP files using '.../...//' seq...
Nov 4, 2024This CVE describes a path traversal vulnerability (CWE-35) in Multi-DNC software that allows attackers to access files outside the intended directory ...
Oct 6, 2024This vulnerability allows attackers to perform path traversal attacks via specially crafted URIs in NVIDIA networking products' web interfaces. Succes...
Aug 12, 2024This vulnerability allows attackers to perform path traversal attacks on the /modules/messaging/ endpoint in Splunk Enterprise on Windows. This could ...
Jul 1, 2024This path traversal vulnerability in Huawei home music systems allows attackers to delete or modify files by manipulating file paths. It affects users...
Dec 28, 2024This path traversal vulnerability in the Barcode Scanner with Inventory & Order Manager WordPress plugin allows attackers to access files outside the ...
Nov 6, 2025This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to overwrite sensitive files by manipulating file paths in H...
Feb 12, 2025This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to overwrite sensitive files by manipulating file paths in H...
Feb 12, 2025This CVE describes a path traversal vulnerability in Axis camera systems' VAPIX API manageoverlayimage.cgi endpoint that allows authenticated users wi...
Nov 21, 2023This path traversal vulnerability in Hitachi Vantara Pentaho Data Integration & Analytics allows attackers to access files outside restricted director...
Apr 16, 2025This path traversal vulnerability in the AA-Team Pro Bulk Watermark WordPress plugin allows attackers to access files outside the intended directory u...
Dec 31, 2025This CVE describes a path traversal vulnerability in Dell PowerProtect Data Domain systems where attackers can use '.../...//' sequences to access una...
Oct 7, 2025A path traversal vulnerability in the miniOrange Prevent files/folders access WordPress plugin allows attackers to bypass file access restrictions and...
Aug 20, 2025This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to delete sensitive files by manipulating HTTP requests. It ...
Feb 12, 2025This path traversal vulnerability in Q-Free MaxTime allows authenticated remote attackers to delete sensitive files via crafted HTTP requests. It affe...
Feb 12, 2025This path traversal vulnerability in the Eventin WordPress plugin allows attackers to access files outside the intended directory using '.../...//' se...
Dec 31, 2024This path traversal vulnerability in Advanced Database Cleaner PRO WordPress plugin allows attackers to access files outside the intended directory us...
Jan 7, 2026This CVE describes a path traversal vulnerability in Axis ACAP configuration files that could allow privilege escalation. It affects Axis devices conf...
Nov 11, 2025A path traversal vulnerability in Splunk Enterprise and Cloud Platform allows low-privileged users to delete arbitrary files via a malicious payload o...
Jul 7, 2025A path traversal vulnerability in usbmuxd allows local users to escalate privileges to the service user account. This affects systems running vulnerab...
Dec 10, 2025About CWE-35 (CWE-35)
Our database tracks 62 CVEs classified as CWE-35, with 5 rated critical and 34 rated high severity. The average CVSS score for CWE-35 vulnerabilities is 7.0.
External reference: View CWE-35 on MITRE CWE →
Monitor CWE-35 Vulnerabilities
Get alerted when new CWE-35 CVEs affect your infrastructure.
Start Monitoring Free