Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2024-25154
Improper URL validation leads to path traversal in FileCatalyst Direct 3.8.8 and earlier allowing an encoded payload to cause the web server to retur…
Filecatalyst Direct
3.8.9+
CRITICAL 9.9
CVE-2024-27317EPSS 57%
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu…
Pulsar
2.10.6 / 2.11.4+
CRITICAL 9.0
CVE-2024-21400
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Confidental Containers
0.3.3+
MEDIUM 6.5
CVE-2024-1303
Incorrectly limiting the path to a restricted directory vulnerability in Badger Meter Monitool that affects versions up to 4.6.3 and earlier. This vu…
Monitool
4.7+
MEDIUM 6.5
CVE-2024-27279
Directory traversal vulnerability exists in a-blog cms Ver.3.1.x series Ver.3.1.9 and earlier, Ver.3.0.x series Ver.3.0.30 and earlier, Ver.2.11.x se…
A Blog Cms
after 3.1.9
HIGH 7.2
CVE-2024-27121
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the …
Mitigation only
HIGH 7.5
CVE-2024-2318
A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of …
Zkbio Media
Mitigation only
HIGH 7.1
CVE-2024-23216
A path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. …
macOS
12.7.4 / 13.6.5+
CRITICAL 9.1
CVE-2024-0818
Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6
Paddlepaddle
2.6.0+
CRITICAL 9.8
CVE-2024-28222
In Veritas NetBackup before 8.1.2 and NetBackup Appliance before 3.1.2, the BPCD process inadequately validates the file path, allowing an unauthenti…
Netbackup
3.1.2 / 8.1.2+
HIGH 7.5
CVE-2024-27765
Directory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateControlle…
Jeewms
after 3.7
CRITICAL 9.8
CVE-2024-27764
An issue in Jeewms v.3.7 and before allows a remote attacker to escalate privileges via the AuthInterceptor component.
Jeewms
after 3.7
CRITICAL 9.1
CVE-2024-25614
There is an arbitrary file deletion vulnerability in the CLI used by ArubaOS. Successful exploitation of this vulnerability results in the ability to…
Arubaos
8.10.0.10 / 8.11.2.1+
HIGH 7.5
CVE-2024-25164
iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionali…
Idurar
No fix yet
HIGH 7.3
CVE-2024-27199 KEVEPSS 100%
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
Teamcity
2023.11.4+
HIGH 8.1
CVE-2024-28088
LangChain through 0.1.10 allows ../ directory traversal by an actor who is able to control the final part of the path parameter in a load_chain call.…
Langchain
0.1.12+
HIGH 7.5
CVE-2024-24307
Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attack…
Product Designer
1.178.36+
HIGH 8.8
CVE-2024-25386
Directory Traversal vulnerability in DICOM® Connectivity Framework by laurelbridge before v.2.7.6b allows a remote attacker to execute arbitrary code…
Mitigation only
MEDIUM 5.3
CVE-2023-38366
IBM Filenet Content Manager Component 5.5.8.0, 5.5.10.0, and 5.5.11.0 could allow a remote attacker to traverse directories on the system. An attacke…
Filenet Content Manager
Mitigation only
MEDIUM 5.5
CVE-2024-2045
Session version 1.17.5 allows obtaining internal application files and public
files from the user's device without the user's consent. This is possi…
Session
No fix yet
CRITICAL 9.8
CVE-2024-25830EPSS 24%
F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker…
Datacube3 Firmware
No fix yet
HIGH 8.1
CVE-2024-25006
XenForo before 2.2.14 allows Directory Traversal (with write access) by an authenticated user who has permissions to administer styles, and uses a ZI…
Xenforo
2.2.14+
CRITICAL 9.1
CVE-2024-25065EPSS 48%
Possible path traversal in Apache OFBiz allowing authentication bypass.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Ofbiz
18.12.12+
MEDIUM 5.3
CVE-2024-23946
Possible path traversal in Apache OFBiz allowing file inclusion.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Ofbiz
18.12.12+
HIGH 7.1
CVE-2024-25859
A path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and execute arbi…
Blesta
5.9.2+
HIGH 8.1
CVE-2024-0763
Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would …
Anythingllm
1.0.0+
HIGH 7.5
CVE-2024-25711
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclos…
Fedora
256+
HIGH 8.8
CVE-2024-27081
ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHo…
Esphome
Patch available
HIGH 8.8
CVE-2024-1886
This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage.
Webos Signage
Mitigation only
MEDIUM 6.5
CVE-2024-1165
The Brizy – Page Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.4.39 via the 'id'. This ma…
Brizy
2.4.40+