Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2025-13645
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_fi…
Modula Image Gallery
2.13.3+
MEDIUM 6.3
CVE-2025-13875
A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file src/main/java/com/yohann/ocih…
Mitigation only
HIGH 7.8
CVE-2025-13876
A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the co…
Hd Video Player All Formats
No fix yet
CRITICAL 9.1
CVE-2025-66410
Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causi…
Gin Vue Admin
after 2.8.6
HIGH 8.5
CVE-2025-66300
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "…
Grav
1.8.0+
MEDIUM 6.8
CVE-2025-66302
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A path traversal vulnerability has been identified in Grav CMS, allowing authenticated att…
Grav
1.8.0+
HIGH 8.8
CVE-2025-66295
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and su…
Grav
1.8.0+
HIGH 8.6
CVE-2025-66206
Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, certain requests were vulnerable to path traversal attacks, wherein s…
Frappe
14.99.2 / 15.86.0+
HIGH 7.5
CVE-2025-65838
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
Publiccms
No fix yet
HIGH 7.1
CVE-2025-63365
SoftSea EPUB File Reader 1.0.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the EPUB file processing component, specifically …
Epub File Reader
Mitigation only
HIGH 8.8
CVE-2025-13816
A security vulnerability has been detected in moxi159753 Mogu Blog v2 up to 5.2. The impacted element is the function FileOperation.unzip of the file…
Mogublog
after 5.2
HIGH 7.5
CVE-2025-13810
A vulnerability was found in jsnjfz WebStack-Guns 1.0. This affects the function renderPicture of the file src/main/java/com/jsnjfz/manage/modular/sy…
Webstack Guns
No fix yet
MEDIUM 6.5
CVE-2025-13791
A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org/scadabr/vo/exporter/ZIPProje…
Scada Lts
after 2.7.8.1
HIGH 8.0
CVE-2025-12638
Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extracting tar archives. The vulnerabi…
Mitigation only
HIGH 7.3
CVE-2025-59890
Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an atta…
Mitigation only
CRITICAL 9.8
CVE-2025-66262
Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300…
Mozart Next 100 Firmware
Mitigation only
CRITICAL 9.1
CVE-2025-66251
Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 30…
Mozart Next 100 Firmware
No fix yet
HIGH 8.7
CVE-2025-65952
Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a path traversal vulnerability e…
Patch available
HIGH 8.7
CVE-2025-34350
UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Doc Flow feature’s 'arc' endpoi…
Mitigation only
MEDIUM 6.9
CVE-2025-59372
A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could exploit this vulnerability to wri…
Mitigation only
CRITICAL 9.2
CVE-2025-59366EPSS 16%
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effect of the Samba functionality…
Mitigation only
HIGH 8.2
CVE-2025-12003
A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact the integrity of the device.…
Mitigation only
CRITICAL 9.9
CVE-2025-54347
A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows an attack…
Pingalert Application Server
6.1.1.6+
HIGH 8.1
CVE-2025-60915
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a pat…
Openatlas
after 8.12.0
MEDIUM 5.3
CVE-2025-12972
Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option is omitted, the plugin uses un…
Fluent Bit
Mitigation only
MEDIUM 5.5
CVE-2025-31248
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, macOS Sono…
macOS
13.7.3 / 14.7.3+
CRITICAL 9.3
CVE-2025-34320
BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize input path segments. This allow…
Mitigation only
HIGH 8.1
CVE-2025-13435
A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of the file /resty-httpclient/sr…
Resty
after 1.3.1
HIGH 7.8
CVE-2025-11001EPSS 27%
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code …
7 Zip
Mitigation only
HIGH 7.5
CVE-2025-63371
Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specific…
Onecommander
Mitigation only