CWE-35
- 6
- vulnerabilities tracked
- 2
- critical
- 17 August 2026
- latest publication
cve
Vulnerability watch
idvulnerabilityseveritypublished
CVE-2026-59909Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.Dell Objectscale High CVSS 7.1 CVE-2026-28157Subscriber Path Traversal in Do Lasso <= 358 versions. High CVSS 7.5 CVE-2026-13716Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.Craftycontrol Crafty Controller Critical CVSS 9.1 CVE-2026-69109A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.NVD analysis in progress High CVSS 7.5 CVE-2026-59115'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.Microsoft Entra Provisioning Service Critical CVSS 9.9 CVE-2025-60835An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. High CVSS 7.8