Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-10468
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Beyaz Computer CityPlus allows Path Traversal.
This …
Mitigation only
CRITICAL 9.8
CVE-2025-59352
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and HTTP APIs allow peers to send…
Dragonfly
2.1.0+
CRITICAL 9.8
CVE-2025-59304
A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote Code Execution via a crafted…
Swetrix
after 4.0.0
MEDIUM 6.5
CVE-2025-35430
CISA Thorium does not adequately validate the paths of downloaded files via 'download_ephemeral' and 'download_children'. A remote, authenticated att…
Thorium
1.1.2+
MEDIUM 6.5
CVE-2025-9215
The StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More plugin for WordPress is vulnerable to Path …
Mitigation only
MEDIUM 6.6
CVE-2025-10050
The Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the…
Mitigation only
HIGH 7.5
CVE-2025-34185
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a pre-authentication file disclosure vulnerability via the 'db_log' POST parameter. Remote atta…
Eve X1 Server Firmware
after 4.7.18.0
MEDIUM 6.9
CVE-2025-59336
Luanox is a module host for Lua packages. Prior to 0.1.1, a file traversal vulnerability can cause potential denial of service by overwriting Phoenix…
Patch available
MEDIUM 5.5
CVE-2025-43314
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, macOS Sono…
macOS
14.8 / 15.7+
MEDIUM 5.5
CVE-2025-43190
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26, macOS Se…
Ipados
14.8 / 15.7+
HIGH 7.5
CVE-2025-59056
FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web…
Freepbx
15.0.38 / 16.0.41+
HIGH 7.5
CVE-2025-10472
A vulnerability has been found in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function download_video/stream_video of the fi…
Moneyprinterturbo
after 1.2.6
MEDIUM 6.3
CVE-2025-49089
wangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.
Moneyprinterturbo
Mitigation only
HIGH 7.2
CVE-2025-10176
The The Hack Repair Guy's Plugin Archiver plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in t…
Mitigation only
MEDIUM 5.3
CVE-2025-10273
A vulnerability was identified in erjinzhi 10OA 1.0. Affected by this vulnerability is an unknown functionality of the file /view/file.aspx. Such man…
10oa
No fix yet
CRITICAL 10.0
CVE-2025-58321
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
Dialink
1.8.0.0+
HIGH 7.3
CVE-2025-58320EPSS 14%
Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
Dialink
1.8.0.0+
HIGH 8.7
CVE-2025-9918
A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.53.2, and all prior versions)…
Mitigation only
HIGH 8.0
CVE-2025-9693
The User Meta – User Profile Builder and User management plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil…
Mitigation only
HIGH 7.5
CVE-2025-10236
A vulnerability has been found in binary-husky gpt_academic up to 3.91. Impacted is the function merge_tex_files_ of the file crazy_functions/latex_f…
Gpt Academic
after 3.91
MEDIUM 5.4
CVE-2025-10232
A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the file plugin/filemanager/controll…
Mitigation only
HIGH 7.5
CVE-2025-59049
Mockoon provides way to design and run mock APIs. Prior to version 9.2.0, a mock API configuration for static file serving follows the same approach …
Patch available
MEDIUM 5.6
CVE-2025-29592
oasys v1.1 is vulnerable to Directory Traversal in ProcedureController.
Oa System
No fix yet
HIGH 8.8
CVE-2025-41714
The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an authenticated attacker can ca…
Mitigation only
CRITICAL 9.8
CVE-2025-23343
The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A successful exploit of this vulner…
Nvdebug
1.7.0+
MEDIUM 6.8
CVE-2025-47415
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CRESTRON TOUCHSCREENS x70 allows Relative Path Traver…
Mitigation only
CRITICAL 10.0
CVE-2025-54261EPSS 21%
ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traver…
Coldfusion
Mitigation only
HIGH 8.8
CVE-2025-58755
MONAI (Medical Open Network for AI) is an AI toolkit for health care imaging. The extractall function `zip_file.extractall(output_dir)` is used direc…
Medical Open Network For Ai
after 1.5.0
MEDIUM 5.3
CVE-2025-58751
Vite is a frontend tooling framework for JavaScript. Prior to versions 7.1.5, 7.0.7, 6.3.6, and 5.4.20, files starting with the same name with the pu…
Vite
5.4.20 / 6.3.6+
CRITICAL 9.2
CVE-2025-5993
ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit vulnerable para…
Mitigation only