Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-66449
ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary f…
Convertx
0.16.0+
HIGH 8.8
CVE-2025-58173
FreshRSS is a self-hosted RSS feed aggregator. In versions 1.23.0 through 1.27.0, using a path traversal inside the `language` user configuration par…
Freshrss
1.27.1+
HIGH 8.8
CVE-2025-60786
A Zip Slip vulnerability in the import a Project component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via uploading a c…
Icescrum
after 7.54
HIGH 8.7
CVE-2025-34181
NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacke…
Mitigation only
CRITICAL 9.8
CVE-2025-14704EPSS 12%
A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The m…
N3 Firmware
after 2.0.25
MEDIUM 5.3
CVE-2025-14699
A security vulnerability has been detected in Municorn FAX App 3.27.0 on Android. This vulnerability affects unknown code of the component biz.faxapp…
Mitigation only
MEDIUM 5.3
CVE-2025-14617
A vulnerability has been found in Jehovahs Witnesses JW Library App up to 15.5.1 on Android. Affected is an unknown function of the component org.jw.…
Mitigation only
MEDIUM 5.5
CVE-2025-43463
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3, macOS So…
macOS
14.8.3 / 15.7.3+
MEDIUM 5.5
CVE-2025-43465
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.1. An app may b…
macOS
26.1+
HIGH 7.2
CVE-2025-67818
An issue was discovered in Weaviate OSS before 1.33.4. An attacker with access to insert data into the database can craft an entry name with an absol…
Weaviate
1.33.4+
MEDIUM 6.5
CVE-2025-12960
The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.0.1 via the `href` parameter i…
Mitigation only
MEDIUM 6.5
CVE-2025-13891
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.13.3. Thi…
Mitigation only
CRITICAL 9.8
CVE-2025-14344
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'p…
Mitigation only
HIGH 8.8
CVE-2025-12824
The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderb…
Mitigation only
HIGH 8.7
CVE-2024-58310
APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manip…
No fix yet
HIGH 7.5
CVE-2024-58312
xbtitFM 4.1.18 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL par…
Xbtitfm
No fix yet
HIGH 8.8
CVE-2025-66429
An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allows for overwrite of an arbitra…
Cpanel
126.0.37 / 130.0.16+
MEDIUM 6.5
CVE-2025-14293
The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 via the 'downloadCustomUpload…
Mitigation only
HIGH 7.5
CVE-2025-67742
In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
Teamcity
2025.11+
CRITICAL 9.1
CVE-2025-14520
A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/inde…
Hfly
after 2016-05-11
HIGH 7.5
CVE-2025-14521
A security vulnerability has been detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected element is an unknown function…
Hfly
after 2016-05-11
MEDIUM 6.5
CVE-2025-67720
Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames received from Telegram messa…
Patch available
CRITICAL 9.1
CVE-2020-36898
QiHang Media Web Digital Signage 3.0.9 contains an unauthenticated file deletion vulnerability in the QH.aspx endpoint that allows remote attackers t…
Qihang Media Web Digital Signage
No fix yet
HIGH 7.5
CVE-2020-36893
Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files …
I Media Server Digital Signage
No fix yet
HIGH 8.1
CVE-2020-36883
SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backu…
Fusion Digital Signage
after 3.4.8
HIGH 7.5
CVE-2025-56430
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-…
Fearlesscms
No fix yet
HIGH 7.5
CVE-2025-56431
Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a denial of service via the plugin-…
Fearlesscms
No fix yet
MEDIUM 6.5
CVE-2025-65814
A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory trav…
Office App Edit Word\, Pdf File
No fix yet
MEDIUM 6.5
CVE-2025-65815
A lack of security checks in the file import process of AB TECHNOLOGY Document Reader: PDF, DOC, PPT v65.0 allows attackers to execute a directory tr…
Document Reader\
No fix yet
CRITICAL 9.1
CVE-2025-65792
DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
Datagear
No fix yet