CWE-35: CWE-35

62
Total CVEs
5
Critical
34
High
7.0
Avg CVSS

Yearly Trend

2026
6
2025
38
2024
14
2023
3
2020
1

Top Affected Vendors

1 Q Free 5
2 Splunk 3
3 Broadcom 2
4 Axis 2
5 Wpjobportal 1
6 Nlnetlabs 1
7 Microsoft 1
8 Agnai 1
9 Dell 1
10 Parall 1

All CWE-35 CVEs (62)

CVE-2025-30966
5.4

A path traversal vulnerability in the WPJobBoard WordPress plugin allows attackers to access files outside the intended directory. This affects all WP...

Apr 15, 2025
CVE-2025-48081
5.3

This path traversal vulnerability in the Printeers Print & Ship WordPress plugin allows attackers to access files outside the intended directory using...

Aug 27, 2025
CVE-2024-52885
5.0

This directory traversal vulnerability in Check Point's Mobile Access Portal File Share application allows authenticated malicious users to list file ...

Aug 6, 2025
CVE-2025-64253
4.9

This path traversal vulnerability in WordPress Health Check & Troubleshooting plugin allows attackers to access files outside the intended directory u...

Dec 16, 2025
CVE-2025-26357
4.9

This vulnerability allows authenticated remote attackers to read sensitive files on Q-Free MaxTime systems via path traversal attacks. Attackers can a...

Feb 12, 2025
CVE-2025-4956
4.3

A path traversal vulnerability in the AA-Team Pro Bulk Watermark WordPress plugin allows attackers to access files outside the intended directory usin...

Aug 30, 2025
CVE-2024-47170
4.3

CVE-2024-47170 is a path traversal vulnerability in Agnai that allows attackers to read arbitrary JSON files on the server when JSON_STORAGE is enable...

Sep 26, 2024
CVE-2024-0067
4.3

This vulnerability in Axis devices allows attackers to perform path traversal attacks through the VAPIX API ledlimit.cgi endpoint, enabling them to li...

Sep 10, 2024
CVE-2025-52712
4.2

This path traversal vulnerability in BoldGrid's Post and Page Builder WordPress plugin allows attackers to access files outside the intended directory...

Aug 14, 2025
CVE-2025-58381
2.3

This vulnerability in Brocade Fabric OS allows authenticated administrators to abuse shell commands (source, ping6, sleep, disown, wait) to manipulate...

Feb 3, 2026
CVE-2025-58380
2.3

This vulnerability allows authenticated administrators on Brocade Fabric OS to use the 'grep' shell command for directory traversal, potentially acces...

Feb 3, 2026
CVE-2025-59099
N/A

This path traversal vulnerability in CompactWebServer allows unauthenticated attackers to read arbitrary files on the file system, including sensitive...

Jan 26, 2026

About CWE-35 (CWE-35)

Our database tracks 62 CVEs classified as CWE-35, with 5 rated critical and 34 rated high severity. The average CVSS score for CWE-35 vulnerabilities is 7.0.

External reference: View CWE-35 on MITRE CWE →

Monitor CWE-35 Vulnerabilities

Get alerted when new CWE-35 CVEs affect your infrastructure.

Start Monitoring Free