compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--
Hyland Alfresco Transformation Service allows unauthenticated attackers to achieve both arbitrary file read and server-s
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated remote at
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Win
An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to
A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file rea
The JetFormBuilder plugin for WordPress is vulnerable to arbitrary file read via path traversal in all versions up to, a
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, on Windows the
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the Se
Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{file
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell c
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoin
The Avada Builder plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.15.2
Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set.
RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin stati
pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary lo
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers
A security vulnerability has been detected in Deepractice PromptX up to 2.4.0. The affected element is the function read
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "n
DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read
The ARMember plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.0.27 via
An issue was discovered in the Shared Account Synchronization component of PaperCut MF (version 25.0.4). The application
Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat
QOCA aim AI Medical Cloud Platform developed by Quanta Computer has a Path Traversal vulnerability, allowing authenticat
A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully
A vulnerability allowing an authenticated user with the Backup Administrator role to write arbitrary files on Linux-base
Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr
Tobit Laboratories AG TeamDavid's Webbox is vulnerable to a path traversal vulnerability in the archive creation funct
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th
Frequently Asked Questions
What is CWE-36?
CWE-36 (CWE-36) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-36?
There are 35 CVE records associated with CWE-36 in our database. Of these, 0 are critical severity, 14 are high severity, and 17 are medium severity.
How can I protect against CWE-36 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-36 using AI-powered security agents.
Detect CWE-36 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-36 vulnerabilities across your infrastructure.
Get Started