Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-35

8
CRITICAL
15
HIGH
12
MEDIUM
3
LOW
41 CVEs
9.9
CVE-2025-59793

Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica

9.9
CVE-2026-45661

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.5 and earlier, a critical path traversal vulnerab

9.9
CVE-2026-59115

'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges ove

9.8
CVE-2026-6074

Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_fi

9.6
CVE-2026-52703

Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

9.1
CVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an atta

9.1
CVE-2026-13716

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to u

9.0
CVE-2026-40128

SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon

8.8
CVE-2026-20034

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote att

8.8
CVE-2026-45495

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

8.8
CVE-2026-42661

Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.

8.7
CVE-2026-42930

When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Applia

8.4
CVE-2026-25705

A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-ra

8.1
CVE-2026-52707

Unauthenticated Local File Inclusion in Kastell <= 2.0 versions.

7.8
CVE-2026-44933

`PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) i

7.8
CVE-2025-60835

An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.

7.7
CVE-2025-67914

Path Traversal: '.../...//' vulnerability in beeteam368 VidMov vidmov allows Path Traversal.This issue affects VidMov: f

7.5
CVE-2025-68428

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loa

7.5
CVE-2026-25397

Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerc

7.5
CVE-2026-49112

Unauthenticated Path Traversal in Shared Files <= 1.7.64 versions.

7.5
CVE-2026-69109

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v

7.5
CVE-2026-28157

Subscriber Path Traversal in Do Lasso <= 358 versions.

7.1
CVE-2026-59909

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l

6.8
CVE-2026-0205

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted ser

6.8
CVE-2026-24464

When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that

6.7
CVE-2026-26124

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

6.7
CVE-2026-0804

An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote

6.5
CVE-2026-49779

Path Traversal: '.../...//' vulnerability in Addify Tax Exempt for WooCommerce allows Path Traversal. This issue affect

6.5
CVE-2026-66695

Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.

6.4
CVE-2025-46256

Path Traversal: '.../...//' vulnerability in SigmaPlugin Advanced Database Cleaner PRO allows Path Traversal.This issue

5.3
CVE-2025-69325

Path Traversal: '.../...//' vulnerability in primersoftware Primer MyData for Woocommerce primer-mydata allows Path Trav

5.0
CVE-2026-32415

Path Traversal: '.../...//' vulnerability in Bogdan Bendziukov Squeeze squeeze allows Path Traversal.This issue affects

4.6
CVE-2026-1763

Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions.

4.4
CVE-2026-28265

PowerStore, contains a Path Traversal vulnerability in the Service user. A low privileged attacker with local access cou

4.2
CVE-2026-24315

SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain,

3.3
CVE-2026-56089

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with l

2.3
CVE-2025-58380

A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the

2.3
CVE-2025-58381

A vulnerability in Brocade Fabric OS before 9.2.1c2 could allow an authenticated attacker with admin privileges using

CVE-2025-59099

The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a

CVE-2026-42274

Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall

CVE-2025-59181

Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio

Frequently Asked Questions

What is CWE-35?

CWE-35 (CWE-35) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-35?

There are 41 CVE records associated with CWE-35 in our database. Of these, 8 are critical severity, 15 are high severity, and 12 are medium severity.

How can I protect against CWE-35 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-35 using AI-powered security agents.

Detect CWE-35 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-35 vulnerabilities across your infrastructure.

Get Started