boxscore/security
CWE · referenceWeaknesses · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CWE-35

Weakness type CWE-35 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.

Totals
CVEs all-timeCVEs YTDKEV all-time
21201

Monthly trend

▂▁▁▁▁▂▁▁▁▄▇▄█

2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 1 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 3 · 2026-06 6 · 2026-07 3 · 2026-08 7

Top CVEs

Ranked by KEV → EPSS → CVSS (§6)
CVECVSSEPSS %ileKEVTitle
CVE-2025-80888.499.8KEVPath traversal vulnerability in WinRAR
CVE-2025-684289.280.2jsPDF has Local File Inclusion/Path Traversal vulnerability
CVE-2026-454958.859.7Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-456619.948.8Dokploy: Remote Code Execution through Path Traversal
CVE-2026-591159.947.7Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
CVE-2026-137169.145.1Path Traversal: '.../...//' in Crafty Controller
CVE-2026-527078.140.4WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability
CVE-2026-691098.738.4
CVE-2026-401289.037.9Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
CVE-2026-527039.636.5WordPress FastDup plugin <= 2.7.2 - Path Traversal vulnerability
CVE-2026-426618.831.7WordPress WP Customer Area plugin <= 8.3.4 - Path Traversal vulnerability
CVE-2026-281577.531.4WordPress Do Lasso plugin <= 358 - Path Traversal vulnerability
CVE-2026-497796.527.4WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability
CVE-2026-491127.525.5WordPress Shared Files plugin <= 1.7.64 - Path Traversal vulnerability
CVE-2026-666956.519.6WordPress W3 Total Cache plugin <= 2.10.2 - Path Traversal vulnerability
CVE-2025-591814.819.0Path traversal Vulnerability
CVE-2026-449338.512.8Path Traversal in Plugin Loading in libzypp
CVE-2026-243154.27.2Path Traversal Vulnerability in SAP Fiori (launchpad)
CVE-2025-608357.84.5
CVE-2026-560893.33.5

Most-affected vendors

Vendors with the most CVEs of this type
VendorCVEs
dell2
microsoft2
sap_se2
addify1
aguilatechnologies1
arcadia technology1
boldgrid1
dokploy1
ericsson1
lasso analytics1
mikado-themes1
ninja team1
parallax1
siemens1
suse1