Skip to main content

CWE archive

CWE-35 CVEs

Programmatic archive

172 CVEs tagged with CWE-3520 Critical, 78 High, 73 Medium, 1 Low, 0 Unrated.

CVE-2025-59181

Published Jul 27, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directo…

CVSS 4.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-60835

Published Jul 22, 2026

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

CVSS 7.8 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-49779

Published Jul 2, 2026

Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affects Tax Exempt for WooCommerce: from n/a before 1.9.5.

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-52707

Published Jun 17, 2026

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-52703

Published Jun 15, 2026

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-49112

Published Jun 15, 2026

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-42661

Published Jun 15, 2026

Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-40128

Published Jun 9, 2026

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabli…

CVSS 9.0 · Critical
evidence mentions
4
Buzz score
32.6

CVE-2026-24315

Published Jun 9, 2026

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, this when opened by the user could compromise accounts by s…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-45661

Published May 29, 2026

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerability exists in Dokploy v0.26.5 that allows authenticated u…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-44933

Published May 20, 2026

`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) in standard configurations or when using `--root`. If the ch…

CVSS 8.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-7302

Published May 18, 2026

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process h…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-25705

Published May 13, 2026

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injec…

CVSS 8.4 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-0804

Published May 12, 2026

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to potential privilege escalation. This vulnerability can only be…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42274

Published May 8, 2026

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request…

CVSS 7.8 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-20034

Published May 6, 2026

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. T…

CVSS 8.8 · High
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2026-6074

Published Apr 23, 2026

Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_file.php endpoint used for Debug Logs downloads. An unauthent…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-28265

Published Apr 1, 2026

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modif…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-25397

Published Mar 25, 2026

Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader fo…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-32415

Published Mar 13, 2026

Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects Squeeze: from n/a through <= 1.7.7.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 172 CVEsPage 1 of 7