Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2025-42906
SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from ad…
Mitigation only
HIGH 8.8
CVE-2025-9713EPSS 15%
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User int…
Endpoint Manager
2024+
CRITICAL 9.1
CVE-2025-11631
A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDo…
Docsys
after 2.02.36
CRITICAL 9.8
CVE-2025-11630
A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component Fil…
Docsys
after 2.02.36
HIGH 7.5
CVE-2025-61884 KEVEPSS 98%
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3…
Configurator
after 12.2.14
HIGH 8.8
CVE-2025-11607
A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controll…
Moneyprinterturbo
after 1.2.6
CRITICAL 9.8
CVE-2025-6439
The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress theme, is vulnerable to arbitrar…
Mitigation only
HIGH 7.8
CVE-2025-21048
Relative path traversal in Knox Enterprise prior to SMR Oct-2025 Release 1 allows local attackers to execute arbitrary code.
Android
Mitigation only
MEDIUM 6.4
CVE-2025-35053
Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedPDF' command that allow an aut…
Project Center
after 2024.3
HIGH 8.8
CVE-2025-35055
Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrary file to any location writab…
Project Center
2023.1+
MEDIUM 5.0
CVE-2025-35056
Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and returns an image of the spec…
Project Center
2024.1+
HIGH 7.2
CVE-2025-34248
D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/global/database/deleteBackup due t…
Mitigation only
CRITICAL 9.6
CVE-2025-10284
BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting …
Mitigation only
CRITICAL 9.6
CVE-2025-10283
BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
Mitigation only
MEDIUM 6.5
CVE-2025-39664
Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define…
Checkmk
2.2.0+
CRITICAL 9.8
CVE-2025-7526
The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due …
Mitigation only
CRITICAL 9.9
CVE-2025-61913EPSS 12%
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i…
Flowise
3.0.8+
HIGH 8.1
CVE-2025-61784
LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat A…
Llama Factory
0.9.4+
MEDIUM 6.0
CVE-2025-43934
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 release version…
Data Domain Operating System
7.10.1.70 / 7.13.1.40+
HIGH 7.5
CVE-2025-43889
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4, LTS2024 release Versions 7.1…
Data Domain Operating System
7.10.1.70 / 7.13.1.40+
HIGH 8.1
CVE-2025-40889
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters. An authenticated u…
Cmc
25.2.0+
MEDIUM 5.4
CVE-2025-3718
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter. …
Cmc
25.2.0+
MEDIUM 5.7
CVE-2025-60969
Directory Traversal vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4.00 allows attackers to gain sen…
Sonoma D12 Firmware
Mitigation only
MEDIUM 5.3
CVE-2025-11336
A security vulnerability has been detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. Affected by this issue is some unknown…
Mitigation only
MEDIUM 5.3
CVE-2025-11337
A vulnerability was detected in Four-Faith Water Conservancy Informatization Platform up to 2.2. This affects an unknown part of the file /aloneRepor…
Mitigation only
HIGH 7.5
CVE-2025-58591
A remote, unauthorized attacker can brute force folders and files and read them like private keys or configurations, making the application vulnerabl…
Baggage Analytics
Mitigation only
HIGH 7.5
CVE-2025-58590
It's possible to brute force folders and files, what can be used by an attacker to steal sensitve information.
Baggage Analytics
after 4.6.1
MEDIUM 5.8
CVE-2025-8917
A vulnerability in allegroai/clearml version v2.0.1 allows for path traversal due to improper handling of symbolic and hard links in the `safe_extrac…
Patch available
HIGH 7.8
CVE-2025-8406
ZenML version 0.83.1 is affected by a path traversal vulnerability in the `PathMaterializer` class. The `load` function uses `is_path_within_director…
Zenml
0.84.2+
MEDIUM 6.5
CVE-2025-33034
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulner…
Qsync Central
5.0.0.1+