Reference page — cumulative record through Monday, October 5, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-35
Weakness type CWE-35 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 29 | 28 | 1 |
Monthly trend
▂▁▁▁▁▂▁▁▁▄▇▄█▇▃
2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 6 · 2026-07 3 · 2026-08 7 · 2026-09 6 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2025-8088 | 8.4 | 99.8 | KEV | Path traversal vulnerability in WinRAR |
| CVE-2025-68428 | 9.2 | 81.7 | — | jsPDF has Local File Inclusion/Path Traversal vulnerability |
| CVE-2026-45661 | 9.9 | 63.0 | — | Dokploy: Remote Code Execution through Path Traversal |
| CVE-2026-45495 | 8.8 | 62.7 | — | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
| CVE-2026-59115 | 9.9 | 62.3 | — | Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability |
| CVE-2026-13716 | 9.1 | 55.1 | — | Path Traversal: '.../...//' in Crafty Controller |
| CVE-2026-27557 | 7.5 | 51.8 | — | Path Traversal in /index.php/view_uploaded_iodd_file |
| CVE-2026-40128 | 9.0 | 48.2 | — | Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) |
| CVE-2026-69109 | 8.7 | 48.0 | — | — |
| CVE-2026-42661 | 8.8 | 43.9 | — | WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability |
| CVE-2026-52707 | 8.1 | 42.5 | — | WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability |
| CVE-2026-49112 | 7.5 | 40.9 | — | WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability |
| CVE-2026-52703 | 9.6 | 40.6 | — | WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability |
| CVE-2026-49779 | 6.5 | 36.3 | — | WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability |
| CVE-2026-85310 | 6.5 | 36.3 | — | WordPress Groundhogg plugin <= 4.7.1 - Path Traversal vulnerability |
| CVE-2025-59181 | 4.8 | 35.2 | — | Path traversal Vulnerability |
| CVE-2026-28157 | 7.5 | 32.8 | — | WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability |
| CVE-2026-66695 | 6.5 | 32.6 | — | WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability |
| CVE-2026-82824 | 9.3 | 29.7 | — | Path traversal may allow arbitrary files to be viewed, created, modified, or deleted |
| CVE-2026-21092 | 8.8 | 22.2 | — | — |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| dell | 2 |
| microsoft | 2 |
| samsung mobile | 2 |
| sap_se | 2 |
| addify | 1 |
| adrian tobey | 1 |
| aguilatechnologies | 1 |
| arcadia technology | 1 |
| boldgrid | 1 |
| carlo gavazzi automation | 1 |
| dokploy | 1 |
| ericsson | 1 |
| hitachi industrial equipment systems | 1 |
| lasso analytics | 1 |
| mediatek | 1 |