Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.5
CVE-2024-43271
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themelocation Woo Products Widgets For Elementor allo…
Mitigation only
MEDIUM 5.3
CVE-2024-43281
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in VOID CODERS Void Elementor Post Grid Addon for Elemen…
Mitigation only
CRITICAL 9.1
CVE-2024-43248
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This i…
Bit Form
after 2.6.4
HIGH 8.5
CVE-2024-43221
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Crocoblock JetGridBuilder allows PHP Local File Inclu…
Mitigation only
HIGH 8.5
CVE-2024-43232
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP OnlineSupport, Essential Plugin Timeline and Histo…
Mitigation only
CRITICAL 9.8
CVE-2024-43399
Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analy…
Mobile Security Framework
4.0.7+
MEDIUM 6.8
CVE-2023-5505
The BackWPup plugin for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.0.1 via the job-specific backup folder. Th…
Backwpup
4.0.2+
HIGH 8.2
CVE-2024-43395
CraftOS-PC 2 is a rewrite of the desktop port of CraftOS from the popular Minecraft mod ComputerCraft using C++ and a modified version of PUC Lua, as…
Patch available
HIGH 8.8
CVE-2024-7145
The JetElements plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.6.20 via the 'progress_type' param…
Jetelements
after 2.6.20
HIGH 8.8
CVE-2024-7146
The JetTabs for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.2.3 via the 'switcher_pr…
Mitigation only
HIGH 7.8
CVE-2024-7262 KEV
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.16412 (exclusive) on Windows al…
Wps Office
12.2.0.16412+
HIGH 7.8
CVE-2024-7263
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.17115 (exclusive) on Windows al…
Wps Office
12.2.0.17153+
HIGH 7.8
CVE-2024-43373
webcrack is a tool for reverse engineering javascript. An arbitrary file write vulnerability exists in the webcrack module when processing specifical…
Webcrack
2.14.1+
MEDIUM 5.5
CVE-2024-42680
An issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by entering a singl…
Super Easy Enterprise Management System
after 1.0.0
HIGH 7.5
CVE-2024-27120
A Local File Inclusion vulnerability has been found in ComfortKey, a product of Celsius Benelux. Using this vulnerability, an unauthenticated attacke…
Comfortkey
24.1.2+
MEDIUM 6.8
CVE-2024-39406
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direc…
Commerce
after 2.4.3
HIGH 7.7
CVE-2024-39399
Adobe Commerce versions 2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direc…
Commerce
after 2.4.3
CRITICAL 9.1
CVE-2024-38652EPSS 8%
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a…
Avalanche
Mitigation only
MEDIUM 5.3
CVE-2024-7741
A vulnerability was found in wanglongcn ltcms 1.0.20 and classified as critical. This issue affects the function downloadFile of the file /api/file/d…
Ltcms
No fix yet
HIGH 7.8
CVE-2024-7738
A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown funct…
Markdown Pdf
No fix yet
HIGH 8.5
CVE-2024-6618
In Ocean Data Systems Dream Report, a path traversal vulnerability could allow an attacker to perform remote code execution through the injection of …
Mitigation only
MEDIUM 6.5
CVE-2024-43165
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rashid87 WPSection allows PHP Local File Inclusion.Th…
Mitigation only
HIGH 8.8
CVE-2024-43138
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MagePeople Team Event Manager for WooCommerce allows …
Event Manager And Tickets Selling For Woocommerce
4.2.2+
HIGH 8.8
CVE-2024-43140
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in G5Theme Ultimate Bootstrap Elements for Elementor all…
Ultimate Bootstrap Elements For Elementor
1.4.5+
HIGH 8.8
CVE-2024-43135
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Themewinter WPCafe allows PHP Local File Inclusion.Th…
Wpcafe
2.2.29+
HIGH 8.8
CVE-2024-43129
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPDeveloper BetterDocs allows PHP Local File Inclusio…
Betterdocs
3.5.9+
CRITICAL 9.3
CVE-2024-39651
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPWeb WooCommerce PDF Vouchers allows File Manipulati…
Woocommerce Pdf Vouchers
4.9.5+
MEDIUM 6.5
CVE-2024-42474
Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the…
Streamlit
1.37.0+
HIGH 7.5
CVE-2024-42485
Filament Excel enables excel export for Filament admin resources. The export download route `/filament-excel/{path}` allowed downloading any file wit…
Filament Excel
1.1.14 / 2.3.3+
CRITICAL 9.8
CVE-2023-7249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Trav…
Directory Services
24.1+