Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove
Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_fi
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta
Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Applia
A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-ra
Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.
`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) i
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: f
jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa
Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerc
Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v
Subscriber Path Traversal in Do Lasso <= 358 versions.
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that
'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote
Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affect
Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.
Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue
Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Trav
Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects
Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.
PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou
SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain,
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the
A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using
The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio
Frequently Asked Questions
What is CWE-35?
CWE-35 (CWE-35) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-35?
There are 41 CVE records associated with CWE-35 in our database. Of these, 8 are critical severity, 15 are high severity, and 12 are medium severity.
How can I protect against CWE-35 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-35 using AI-powered security agents.
Detect CWE-35 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-35 vulnerabilities across your infrastructure.
Get Started