Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-22523
Directory Traversal vulnerability in Qiyu iFair version 23.8_ad0 and before, allows remote attackers to obtain sensitive information via uploadimage …
Ifair
after 23.8_ad0
HIGH 7.5
CVE-2024-23334EPSS 77%
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it …
Fedora
3.9.2+
MEDIUM 6.5
CVE-2023-30970
Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated user to read arbitrary files on …
Gotham Blackbird Witchcraft
1.1.0 / 103.30230304.433+
CRITICAL 9.8
CVE-2024-23822
Thruk is a multibackend monitoring webinterface. Prior to 3.12, the Thruk web monitoring application presents a vulnerability in a file upload form …
Thruk
3.12+
CRITICAL 9.8
CVE-2024-23827
Nginx-UI is a web interface to manage Nginx configurations. The Import Certificate feature allows arbitrary write into the system. The feature does n…
Nginx Ui
Mitigation only
CRITICAL 9.8
CVE-2024-0989
A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the fu…
Kuerp
after 1.0.4
CRITICAL 9.9
CVE-2024-0402
An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which a…
GitLab
16.5.8 / 16.6.6+
MEDIUM 6.5
CVE-2023-41474EPSS 38%
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.…
Avalanche
No fix yet
HIGH 7.5
CVE-2024-0882
A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-…
Linkwechat
No fix yet
HIGH 7.8
CVE-2023-52076
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerabili…
Atril
1.26.2+
CRITICAL 9.8
CVE-2024-23897 KEVEPSS 100%
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character followed by a …
Jenkins
2.426.3 / 2.442+
MEDIUM 6.5
CVE-2024-23899
Jenkins Git server Plugin 99.va_0826a_b_cdfa_d and earlier does not disable a feature of its command parser that replaces an '@' character followed b…
Git Server
after 99.va_0826a_b_cdfa_d
HIGH 7.5
CVE-2024-23904
Jenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a file path …
Log Command
after 1.0.2
MEDIUM 5.3
CVE-2024-22204
Whoogle Search is a self-hosted metasearch engine. Versions 0.8.3 and prior have a limited file write vulnerability when the configuration options in…
Whoogle Search
0.8.4+
HIGH 8.1
CVE-2024-23182
Relative path traversal vulnerability in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.…
A Blog Cms
2.10.50 / 2.11.58+
MEDIUM 5.3
CVE-2024-23340
@hono/node-server is an adapter that allows users to run Hono applications on Node.js. Since v1.3.0, @hono/node-server has used its own Request objec…
Node Server
1.4.1+
HIGH 7.8
CVE-2022-45792
Project files may contain malicious contents which the software will use to create files on the filesystem. This allows directory traversal and overw…
Sysmac Studio
1.54.0+
MEDIUM 6.5
CVE-2023-44395
Autolab is a course management service that enables instructors to offer autograded programming assignments to their students over the Web. Path trav…
Autolab
2.12.0+
HIGH 8.8
CVE-2024-23768
Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on certain folders (and the files and datasets in these folde…
Dremio
22.2.3 / 23.2.4+
CRITICAL 9.8
CVE-2024-0769 KEVEPSS 83%
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some un…
Dir 859 Firmware
Mitigation only
MEDIUM 5.3
CVE-2023-35020
IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL…
Sterling Control Center
Patch available
CRITICAL 9.8
CVE-2024-22415
jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve…
Language Server Protocol Integration
2.2.2+
MEDIUM 5.5
CVE-2023-5097
Improper Input Validation vulnerability in HYPR Workforce Access on Windows allows Path Traversal.This issue affects Workforce Access: before 8.7.
Workforce Access
8.7+
HIGH 8.8
CVE-2021-24566
The WooCommerce Currency Switcher FOX WordPress plugin before 1.3.7 was vulnerable to LFI attacks via the "woocs" shortcode.
Fox Currency Switcher Professional For Woocommerce
1.3.7+
CRITICAL 9.8
CVE-2023-6623EPSS 51%
The Essential Blocks WordPress plugin before 4.4.3 does not prevent unauthenticated attackers from overwriting local variables when rendering templat…
Essential Blocks
4.4.3+
MEDIUM 6.5
CVE-2023-46749
Apache Shiro before 1.13.0 or 2.0.0-alpha-4, may be susceptible to a path traversal attack that results in an authentication bypass when used togethe…
Shiro
1.13.0+
HIGH 7.5
CVE-2023-48383
NetVision
Information
airPASS has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can e…
Airpass
Mitigation only
HIGH 7.5
CVE-2023-52288
An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to …
Flaskcode
after 0.0.8
HIGH 7.5
CVE-2023-52289
An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to…
Flaskcode
after 0.0.8
HIGH 7.5
CVE-2023-48166
A directory traversal vulnerability in the SOAP Server integrated in Atos Unify OpenScape Voice V10 before V10R3.26.1 allows a remote attacker to vie…
Openscape Voice
Mitigation only