CWE-36: CWE-36

60
Total CVEs
11
Critical
27
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
8
2025
33
2024
16
2023
3

Top Affected Vendors

1 Lollms 5
2 Uniong 4
3 Microsoft 3
4 Ivanti 3
5 Cht 2
6 Quantatw 2
7 Cisco 2
8 Gotac 2
9 Welltend 1
10 Hyland 1

All CWE-36 CVEs (60)

CVE-2023-3765
10.0

This vulnerability allows attackers to perform absolute path traversal attacks in MLflow deployments prior to version 2.5.0. Attackers can potentially...

Jul 19, 2023
CVE-2025-34392
9.8

This vulnerability in Barracuda Service Center allows attackers to upload malicious WSDL files that bypass URL validation, leading to arbitrary file w...

Dec 10, 2025
CVE-2025-0851
9.8

A path traversal vulnerability in Deep Java Library's ZipUtils.unzip and TarUtils.untar functions allows attackers to write files to arbitrary locatio...

Jan 29, 2025
CVE-2024-13159
KEV EPSS 93.9% 9.8

CVE-2024-13159 is an absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM) that allows remote unauthenticated attackers to access sen...

Jan 14, 2025
CVE-2024-13161
KEV EPSS 89.6% 9.8

This vulnerability allows remote unauthenticated attackers to perform absolute path traversal attacks on Ivanti Endpoint Manager (EPM) systems, potent...

Jan 14, 2025
CVE-2024-10811
EPSS 15.6% 9.8

This vulnerability allows remote unauthenticated attackers to perform absolute path traversal attacks on Ivanti Endpoint Manager (EPM) systems, potent...

Jan 14, 2025
CVE-2024-9924
9.8

This vulnerability allows unauthenticated remote attackers to download arbitrary system files from OAKlouds software by Hgiga, potentially leading to ...

Oct 14, 2024
CVE-2024-20401
9.8

This critical vulnerability in Cisco Secure Email Gateway allows unauthenticated remote attackers to overwrite arbitrary files on the underlying opera...

Jul 17, 2024
CVE-2024-10831
9.1

This vulnerability allows attackers to upload arbitrary files to any location on the server by exploiting path traversal in the file upload endpoint. ...

Mar 20, 2025
CVE-2024-47883
9.1

This vulnerability in the OpenRefine fork of MIT Simile Butterfly server allows attackers to exploit improper URL validation to access files from remo...

Oct 24, 2024
CVE-2024-2362
9.1

A path traversal vulnerability in parisneo/lollms-webui version 9.3 on Windows allows attackers to delete any file on the system by exploiting imprope...

Jun 6, 2024
CVE-2025-7846
8.8

The WordPress User Extra Fields plugin has an arbitrary file deletion vulnerability in all versions up to 16.7. Authenticated attackers with Subscribe...

Oct 31, 2025
CVE-2025-57790
EPSS 51.7% 8.8

This CVE describes a path traversal vulnerability that allows remote attackers to access files outside intended directories, potentially leading to re...

Aug 20, 2025
CVE-2024-8501
8.8

This vulnerability allows any user to download arbitrary files from the rpc_agent's host system by exploiting the download_file method in modelscope/a...

Mar 20, 2025
CVE-2024-21323
8.8

This vulnerability allows remote attackers to execute arbitrary code on Microsoft Defender for IoT systems without authentication. It affects organiza...

Apr 9, 2024
CVE-2024-48248
KEV EPSS 94% 8.6

CVE-2024-48248 is an absolute path traversal vulnerability in NAKIVO Backup & Replication that allows unauthenticated attackers to read arbitrary file...

Mar 4, 2025
CVE-2024-33620
8.6

An absolute path traversal vulnerability in ID Link Manager and FUJITSU Software TIME CREATOR allows unauthenticated remote attackers to read arbitrar...

Jun 18, 2024
CVE-2026-26337
8.2

CVE-2026-26337 is an absolute path traversal vulnerability in Hyland Alfresco Transformation Service that allows unauthenticated attackers to read arb...

Feb 19, 2026
CVE-2025-36574
8.2

Dell Wyse Management Suite versions before 5.2 contain an absolute path traversal vulnerability that allows unauthenticated remote attackers to access...

Jun 10, 2025
CVE-2025-13282
8.1

TenderDocTransfer software from Chunghwa Telecom has two critical vulnerabilities: lack of CSRF protection allows unauthenticated remote attackers to ...

Nov 17, 2025
CVE-2024-12643
8.1

The tbm-client from Chunghwa Telecom has two vulnerabilities: lack of CSRF protection in APIs allowing unauthenticated remote attacks via phishing, an...

Dec 16, 2024
CVE-2024-12646
8.1

The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability due to missing CSRF protection and an Absolute Path Traversal flaw in...

Dec 16, 2024
CVE-2025-36357
8.0

CVE-2025-36357 is a directory traversal vulnerability in IBM Planning Analytics Local that allows authenticated remote attackers to access arbitrary f...

Nov 17, 2025
CVE-2023-40597
7.8

This vulnerability allows attackers to exploit absolute path traversal in Splunk Enterprise to execute arbitrary code from separate disks. It affects ...

Aug 30, 2023
CVE-2026-2753
7.5

An absolute path traversal vulnerability in Navtor NavBox allows unauthenticated remote attackers to read arbitrary files from the filesystem. This af...

Mar 6, 2026
CVE-2026-1330
7.5

MeetingHub software from HAMASTAR Technology contains an absolute path traversal vulnerability that allows unauthenticated remote attackers to read ar...

Jan 22, 2026
CVE-2026-1018
7.5

The Police Statistics Database System developed by Gotac contains an unauthenticated arbitrary file read vulnerability via absolute path traversal. Th...

Jan 16, 2026
CVE-2025-15227
7.5

CVE-2025-15227 is an arbitrary file read vulnerability in BPMFlowWebkit developed by WELLTEND TECHNOLOGY. Unauthenticated remote attackers can exploit...

Dec 29, 2025
CVE-2025-8912
7.5

CVE-2025-8912 is an arbitrary file reading vulnerability in WellChoose's Organization Portal System that allows unauthenticated remote attackers to ex...

Aug 13, 2025
CVE-2024-8497
7.5

This vulnerability allows attackers to read a file containing administrator credentials on Franklin Fueling Systems TS-550 EVO devices. Attackers can ...

Sep 25, 2024
CVE-2024-6250
7.5

An absolute path traversal vulnerability in parisneo/lollms-webui v9.6 allows attackers to read arbitrary files and list directories on Windows system...

Jun 27, 2024
CVE-2024-4881
7.5

A path traversal vulnerability in parisneo/lollms allows attackers to read or delete any file on Windows systems by exploiting improper path validatio...

Jun 6, 2024
CVE-2024-2548
7.5

A path traversal vulnerability in parisneo/lollms-webui allows attackers to read arbitrary files on Windows systems by exploiting inadequate path vali...

Jun 6, 2024
CVE-2025-8213
7.2

The NinjaScanner WordPress plugin contains an arbitrary file deletion vulnerability that allows authenticated attackers with Administrator privileges ...

Jul 31, 2025
CVE-2025-4799
7.2

The WP-DownloadManager plugin for WordPress has a vulnerability allowing authenticated attackers with Administrator privileges to delete arbitrary fil...

Jun 11, 2025
CVE-2023-36786
7.2

CVE-2023-36786 is a remote code execution vulnerability in Skype for Business that allows an attacker to execute arbitrary code on a target system by ...

Oct 10, 2023
CVE-2025-13283
7.1

TenderDocTransfer software has two critical vulnerabilities: lack of CSRF protection allows unauthenticated remote attackers to trigger API calls via ...

Nov 17, 2025
CVE-2024-6854
7.1

This vulnerability in h2oai/h2o-3 version 3.46.0 allows attackers to export trained models to arbitrary locations on the server's filesystem, overwrit...

Mar 20, 2025
CVE-2025-9256
6.5

CVE-2025-9256 is an arbitrary file reading vulnerability in WebITR software developed by Uniong. Remote attackers with regular user privileges can exp...

Aug 22, 2025
CVE-2025-9257
6.5

CVE-2025-9257 is an arbitrary file reading vulnerability in WebITR software developed by Uniong. Remote attackers with regular user privileges can exp...

Aug 22, 2025
CVE-2025-9258
6.5

CVE-2025-9258 is an arbitrary file reading vulnerability in WebITR software developed by Uniong. Remote attackers with regular user privileges can exp...

Aug 22, 2025
CVE-2025-9259
6.5

CVE-2025-9259 is an arbitrary file reading vulnerability in WebITR software developed by Uniong. Remote attackers with regular user privileges can exp...

Aug 22, 2025
CVE-2024-12375
6.5

A local file inclusion vulnerability in automatic1111/stable-diffusion-webui allows attackers to read arbitrary files on the system by sending special...

Mar 20, 2025
CVE-2024-20379
6.5

This vulnerability allows authenticated remote attackers to read arbitrary files from the underlying operating system of Cisco Secure Firewall Managem...

Oct 23, 2024
CVE-2024-7323
6.5

Digiwin EasyFlow .NET has an access control vulnerability combined with insufficient input filtering, allowing authenticated remote attackers to downl...

Aug 2, 2024
CVE-2023-41830
6.5

This CVE describes an improper absolute path traversal vulnerability in Motorola's Ready For application that allows local applications to access file...

May 3, 2024
CVE-2024-45291
6.3

PHPSpreadsheet has a vulnerability where attackers can create malicious XLSX files that cause arbitrary file reads and Server-Side Request Forgery whe...

Oct 7, 2024
CVE-2026-1020
5.3

The Police Statistics Database System developed by Gotac contains an absolute path traversal vulnerability that allows unauthenticated remote attacker...

Jan 16, 2026
CVE-2024-10047
5.3

This vulnerability allows attackers to list arbitrary directories on Windows systems running vulnerable versions of lollms-webui. By sending a special...

Mar 20, 2025
CVE-2024-6097
5.3

This vulnerability allows a local threat actor to disclose sensitive information through absolute path traversal in Progress Telerik Reporting. It aff...

Feb 12, 2025

About CWE-36 (CWE-36)

Our database tracks 60 CVEs classified as CWE-36, with 11 rated critical and 27 rated high severity. The average CVSS score for CWE-36 vulnerabilities is 7.3.

External reference: View CWE-36 on MITRE CWE →

Monitor CWE-36 Vulnerabilities

Get alerted when new CWE-36 CVEs affect your infrastructure.

Start Monitoring Free