CWE-35

Total CVEs
94
Vulnerabilities
Avg CVSS v3
7.1
High
Avg CVSS v2
4.6
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 6
6.4%
High 48
51.1%
Medium 40
42.6%
Low 0
0%

External References

All CVEs (94)

Page 1 of 4
CVSS:9.8(Critical)

This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.

CWE-352024
CVSS:9.8(Critical)

The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.

CWE-352018
CVSS:9.3(Critical)

Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.

CWE-352024
CVSS:9.3(Critical)

Directory Traversal vulnerability in D-Link DAP-1650 Firmware v.1.03 allows a local attacker to escalate privileges via the hedwig.cgi component.

CWE-352024
CVSS:9.1(Critical)

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of directory traversa...

CWE-352020
CVSS:8.8(High)

Path Traversal vulnerability in ilmosys Open Close WooCommerce Store allows PHP Local File Inclusion. This issue affects Open Close WooCommerce Store: from n/a through 4.9.5.

CWE-352025
CVSS:8.8(High)

Path Traversal vulnerability in wpjobportal WP Job Portal allows PHP Local File Inclusion. This issue affects WP Job Portal: from n/a through 2.2.8.

CWE-352025
CVSS:8.8(High)

Path Traversal vulnerability in ElementInvader ElementInvader Addons for Elementor allows PHP Local File Inclusion.This issue affects ElementInvader Addons for Elementor: from n/a through 1.2.6.

CWE-352025
CVSS:8.8(High)

Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking allows PHP Local File Inclusion.This issue affects WP Hotel Booking: from n/a through 2.1.4.

CWE-352024
CVSS:8.8(High)

Agnai is an artificial-intelligence-agnostic multi-user, mult-bot roleplaying chat system. A vulnerability in versions prior to 1.0.330 permits attackers to upload arbitrary files to attacker-chosen l...

CWE-352024
CVSS:8.8(High)

This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.

CWE-352024
CVSS:8.8(High)

NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this...

CWE-352024
CVSS:8.8(High)

Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw c...

CWE-352023
CVSS:8.8(High)

In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an attacker to write to any file to any location of the filesystem, which could lead to remote code execution.

CWE-352023
CVSS:8.6(High)

Path Traversal: '.../...//' vulnerability in Corporate Zen Contact Page With Google Map allows Path Traversal.This issue affects Contact Page With Google Map: from n/a through 1.6.1.

CWE-352024
CVSS:8.6(High)

Path Traversal vulnerability in SMSA Express SMSA Shipping allows Path Traversal.This issue affects SMSA Shipping: from n/a through 2.3.

CWE-352024
CVSS:8.6(High)

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension ...

CWE-352024
CVSS:8.5(High)

Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.

CWE-352024
CVSS:8.5(High)

Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue affects WPLMS: from n/a before 1.9.9.5.2.

CWE-352024
CVSS:8.3(High)

Path Traversal: '.../...//' vulnerability in DeluxeThemes Userpro allows Path Traversal.This issue affects Userpro: from n/a through 5.1.9.

CWE-352024
CVSS:8.1(High)

Path Traversal vulnerability in WHMPress WHMpress allows Path Traversal. This issue affects WHMpress: from 6.2 through revision.

CWE-352025
CVSS:8.1(High)

Path Traversal: '.../...//' vulnerability in ThimPress Ivy School allows PHP Local File Inclusion.This issue affects Ivy School: from n/a through 1.6.0.

CWE-352025
CVSS:8.1(High)

Path Traversal: '.../...//' vulnerability in bslthemes Tastyc allows PHP Local File Inclusion.This issue affects Tastyc: from n/a before 2.5.2.

CWE-352025
CVSS:8.1(High)

Path Traversal vulnerability in NotFound WizShop allows PHP Local File Inclusion. This issue affects WizShop: from n/a through 3.0.2.

CWE-352025