CWE-35
- 6
- vulnérabilités suivies
- 2
- critiques
- 17 août 2026
- dernière publication
cve
Veille des vulnérabilités
identifiantvulnérabilitésévéritépublié
CVE-2026-59909Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.Dell Objectscale Élevée CVSS 7.1 CVE-2026-28157Subscriber Path Traversal in Do Lasso <= 358 versions. Élevée CVSS 7.5 CVE-2026-13716Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.Craftycontrol Crafty Controller Critique CVSS 9.1 CVE-2026-69109A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal vulnerability due to lack of sanitization of user input. This could allow a remote attacker to access arbitrary files on the application.Analyse NVD en cours Élevée CVSS 7.5 CVE-2026-59115'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.Microsoft Entra Provisioning Service Critique CVSS 9.9 CVE-2025-60835An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. Élevée CVSS 7.8