Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-35 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 21 | 20 | 1 |
▂▁▁▁▁▂▁▁▁▄▇▄█
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 6 · 2026-07 3 · 2026-08 7
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-8088 | 8.4 | 99.8 | KEV | Path traversal vulnerability in WinRAR |
| CVE-2025-68428 | 9.2 | 80.2 | — | jsPDF has Local File Inclusion/Path Traversal vulnerability |
| CVE-2026-45495 | 8.8 | 59.7 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-45661 | 9.9 | 48.8 | — | Dokploy: Remote Code Execution through Path Traversal |
| CVE-2026-59115 | 9.9 | 47.7 | — | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability |
| CVE-2026-13716 | 9.1 | 45.1 | — | Path Traversal: '.../...//' in Crafty Controller |
| CVE-2026-52707 | 8.1 | 40.4 | — | WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability |
| CVE-2026-69109 | 8.7 | 38.4 | — | — |
| CVE-2026-40128 | 9.0 | 37.9 | — | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) |
| CVE-2026-52703 | 9.6 | 36.5 | — | WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability |
| CVE-2026-42661 | 8.8 | 31.7 | — | WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability |
| CVE-2026-28157 | 7.5 | 31.4 | — | WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability |
| CVE-2026-49779 | 6.5 | 27.4 | — | WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability |
| CVE-2026-49112 | 7.5 | 25.5 | — | WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability |
| CVE-2026-66695 | 6.5 | 19.6 | — | WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability |
| CVE-2025-59181 | 4.8 | 19.0 | — | Path traversal Vulnerability |
| CVE-2026-44933 | 8.5 | 12.8 | — | Path Traversal in Plugin Loading in libzypp |
| CVE-2026-24315 | 4.2 | 7.2 | — | Path Traversal Vulnerability in SAP Fiori (launchpad) |
| CVE-2025-60835 | 7.8 | 4.5 | — | — |
| CVE-2026-56089 | 3.3 | 3.5 | — | — |
| Vendor | CVEs |
|---|---|
| dell | 2 |
| microsoft | 2 |
| sap_se | 2 |
| addify | 1 |
| aguilatechnologies | 1 |
| arcadia technology | 1 |
| boldgrid | 1 |
| dokploy | 1 |
| ericsson | 1 |
| lasso analytics | 1 |
| mikado-themes | 1 |
| ninja team | 1 |
| parallax | 1 |
| siemens | 1 |
| suse | 1 |