CWE-36: CWE-36

60
Total CVEs
11
Critical
27
High
7.3
Avg CVSS
3
In CISA KEV

Yearly Trend

2026
8
2025
33
2024
16
2023
3

Top Affected Vendors

1 Lollms 5
2 Uniong 4
3 Microsoft 3
4 Ivanti 3
5 Cht 2
6 Quantatw 2
7 Cisco 2
8 Gotac 2
9 Welltend 1
10 Hyland 1

All CWE-36 CVEs (60)

CVE-2025-53392
5.0

This vulnerability in pfSense CE 2.8.0 allows users with the 'WebCfg - Diagnostics: Command' privilege to read arbitrary files through directory trave...

Jun 28, 2025
CVE-2024-57966
5.0

This vulnerability in KDE ark archive utility allows extraction of archive files to arbitrary absolute paths on the filesystem. Attackers can overwrit...

Feb 3, 2025
CVE-2025-14253
4.9

Vitals ESP software from Galaxy Software Services contains an absolute path traversal vulnerability that allows authenticated remote attackers with el...

Dec 8, 2025
CVE-2025-9516
4.9

The atec Debug WordPress plugin contains an arbitrary file read vulnerability that allows authenticated attackers with Administrator privileges to rea...

Sep 4, 2025
CVE-2025-8009
4.9

The Security Ninja WordPress plugin contains an arbitrary file read vulnerability in all versions up to 5.242. Authenticated attackers with Administra...

Jul 24, 2025
CVE-2026-20834
4.6

This CVE describes an absolute path traversal vulnerability in Windows Shell that allows an attacker with physical access to perform spoofing attacks....

Jan 13, 2026
CVE-2025-67898
4.5

MJML versions through 4.18.0 contain a directory traversal vulnerability in the mj-include component, allowing attackers to test for file existence an...

Dec 14, 2025
CVE-2025-15236
4.3

QOCA aim AI Medical Cloud Platform has an absolute path traversal vulnerability that allows authenticated remote attackers to read folder names under ...

Jan 5, 2026
CVE-2025-15237
4.3

CVE-2025-15237 is an absolute path traversal vulnerability in QOCA aim AI Medical Cloud Platform that allows authenticated remote attackers to read fo...

Jan 5, 2026
CVE-2025-14848
4.3

Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, allowing attackers to determine if arbitrary files exist on the system. This ...

Dec 18, 2025

About CWE-36 (CWE-36)

Our database tracks 60 CVEs classified as CWE-36, with 11 rated critical and 27 rated high severity. The average CVSS score for CWE-36 vulnerabilities is 7.3.

External reference: View CWE-36 on MITRE CWE →

Monitor CWE-36 Vulnerabilities

Get alerted when new CWE-36 CVEs affect your infrastructure.

Start Monitoring Free