Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2024-27174
Remote Command program allows an attacker to get Remote Code Execution. This vulnerability can be executed in combination with other vulnerabilities …
No fix yet
CRITICAL 9.8
CVE-2024-27144
The Toshiba printers provide several ways to upload files using the web interface without authentication. An attacker can overwrite any insecure file…
Mitigation only
CRITICAL 9.8
CVE-2024-27145
The Toshiba printers provide several ways to upload files using the admin web interface. An attacker can remotely compromise any Toshiba printer. An …
Mitigation only
MEDIUM 5.3
CVE-2023-35860
A Directory Traversal vulnerability in Modern Campus - Omni CMS 2023.1 allows a remote, unauthenticated attacker to enumerate file system information…
Omni Cms
Mitigation only
HIGH 7.5
CVE-2024-34129
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path T…
Acrobat Reader
24.5.0.33694+
MEDIUM 5.3
CVE-2024-4576
The component listed above contains a vulnerability that allows an attacker to traverse directories and access sensitive files, leading to unauthoriz…
Ebx
after 5.9.25
HIGH 8.1
CVE-2024-37037
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path
Traversal’) vulnerability exists that could allow an authenticated user wi…
Sage Rtu Firmware
Patch available
HIGH 8.1
CVE-2024-5154
A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw…
Cri O
Mitigation only
CRITICAL 9.1
CVE-2024-4315
parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoi…
Patch available
MEDIUM 5.3
CVE-2024-37169
@jmondi/url-to-png is a self-hosted URL to PNG utility. Versions prior to 2.0.3 are vulnerable to arbitrary file read if a threat actor uses the Play…
Patch available
HIGH 8.8
CVE-2024-36418
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in connec…
Suitecrm
7.14.4 / 8.6.1+
MEDIUM 6.5
CVE-2024-35754
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ovic Team Ovic Importer allows Path Traversal.This is…
Ovic Importer
after 1.6.3
MEDIUM 6.5
CVE-2024-35743
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Siteclean SC filechecker allows Path Traversal, File …
Sc Filechecker
after 0.6
MEDIUM 6.5
CVE-2024-35744
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ravidhu Dissanayake Upunzipper allows Path Traversal,…
Upunzipper
after 1.0.0
HIGH 7.5
CVE-2024-35745
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Gabriel Somoza / Joseph Fitzgibbons Strategery Migrat…
Strategery Migrations
after 1.0
CRITICAL 9.1
CVE-2024-35658
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeHigh Checkout Field Editor for WooCommerce (Pro)…
Checkout Field Editor For Woocommerce
3.6.3+
CRITICAL 9.8
CVE-2024-35677
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in StylemixThemes MegaMenu allows PHP Local File Inclusi…
Mega Menu
2.3.13+
MEDIUM 6.5
CVE-2024-35474
A Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server, via setP…
Mitigation only
CRITICAL 9.9
CVE-2024-34762
Vulnerability discovered by executing a planned security audit.
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne…
Mitigation only
HIGH 8.1
CVE-2024-32703
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in reputeinfosystems ARForms arforms.This issue affects …
Arforms
6.4.1+
HIGH 8.1
CVE-2024-32778
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wasiliy Strecker / ContestGallery developer Contest G…
Contest Gallery
21.3.5+
HIGH 8.1
CVE-2024-5637
The Market Exporter plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'remove_files' function …
Market Exporter
2.0.20+
HIGH 8.8
CVE-2024-5481
The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including,…
Photo Gallery
1.8.24+
MEDIUM 5.3
CVE-2024-5550
In h2oai/h2o-3 version 3.40.0.4, an exposure of sensitive information vulnerability exists due to an arbitrary system path lookup feature. This vulne…
H2o
No fix yet
HIGH 8.8
CVE-2024-5187
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for arbitrary file overwrite due t…
Onnx
No fix yet
HIGH 7.5
CVE-2024-4881
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in vers…
Lollms
5.9.0+
CRITICAL 9.8
CVE-2024-3429EPSS 28%
A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` f…
Lollms
9.6+
CRITICAL 9.8
CVE-2024-4320EPSS 34%
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…
Lollms Web Ui
No fix yet
CRITICAL 9.8
CVE-2024-3234
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application i…
Chuanhuchatgpt
20240305+
CRITICAL 9.8
CVE-2024-3322
A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5…
Lollms Web Ui
9.5+