Skip to main content

Threats Tagged 'cwe-35'

View all threats tagged with 'cwe-35'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-35

Threats Tagged 'cwe-35'

Click on any threat for detailed analysis and mitigation recommendations

An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file endpoint allowing the SSH server's private keys to be read.

Join the discussion

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

Join the discussion

CVE-2026-21092 is a path traversal vulnerability in ImsService prior to SMR Sep-2026 Release 1. It allows remote attackers to create image files with system server privileges, potentially enabling unauthorized file creation in privileged locations. No patch or exploit information is currently available.

Join the discussion

CVE-2026-21103 is a path traversal vulnerability in Samsung Mobile's GalaxyDiagnostics component prior to the SMR Sep-2026 Release 1. This flaw allows physical attackers to access files with system privileges on affected Samsung Mobile devices. The vulnerability has a CVSS 4.0 base score of 6.8, indicating medium severity. No specific affected versions or patch information is provided in the available data.

Join the discussion

In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533; Issue ID: MSV-8245.

Join the discussion

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Join the discussion

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

Join the discussion

Dell ObjectScale versions prior to 4.3.0.1 have a path traversal vulnerability (CWE-35) that allows a low privileged local attacker to tamper with information. This vulnerability does not impact confidentiality but can affect integrity and availability. The vulnerability is rated high severity with a CVSS score of 7.1.

Join the discussion

Subscriber Path Traversal in Do Lasso <= 358 versions.

Join the discussion

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.

Join the discussion

Showing 1 to 10 of 68 results

Filters:Tag: cwe-35
Page 1 of 7
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses