Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-23304
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loadin…
Nemo
2.3.2+
HIGH 7.8
CVE-2025-8941
A flaw was found in linux-pam. The pam_namespace module may improperly handle user-controlled paths, allowing local users to exploit symlink attacks …
Mitigation only
HIGH 7.5
CVE-2025-8912
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit …
Organization Portal System
Mitigation only
MEDIUM 6.5
CVE-2025-8909
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to …
Organization Portal System
Mitigation only
MEDIUM 6.5
CVE-2025-0818
Several WordPress plugins using elFinder versions 2.1.64 and prior are vulnerable to Directory Traversal in various versions. This makes it possible …
Mitigation only
MEDIUM 6.5
CVE-2025-55169
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…
Wegia
3.4.8+
MEDIUM 6.5
CVE-2024-52964
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 throu…
Fortimanager
7.0.14 / 7.2.10+
HIGH 7.5
CVE-2025-53793
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
Azure Stack Hub
1.2406.1.23 / 1.2408.1.50+
MEDIUM 5.3
CVE-2025-49559
Adobe Commerce versions 2.4.9-alpha1, 2.4.8-p1, 2.4.7-p6, 2.4.6-p11, 2.4.5-p13, 2.4.4-p14 and earlier are affected by an Improper Limitation of a Pat…
Commerce
1.3.3 / 2.4.4+
MEDIUM 5.3
CVE-2025-55011
Kanboard is project management software that focuses on the Kanban methodology. Prior to version 1.2.47, the createTaskFile method in the API does no…
Kanboard
1.2.47+
HIGH 8.1
CVE-2025-5391
The WooCommerce Purchase Orders plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_…
Mitigation only
MEDIUM 6.9
CVE-2025-42946
Due to directory traversal vulnerability in SAP S/4HANA (Bank Communication Management), an attacker with high privileges and access to a specific tr…
Mitigation only
HIGH 7.5
CVE-2025-25231EPSS 20%
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive inform…
Mitigation only
CRITICAL 9.8
CVE-2025-8815
A vulnerability was found in 猫宁i Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e. It has been classified as critical. Affected is an unknown…
Morning
Mitigation only
MEDIUM 5.4
CVE-2025-8753
A vulnerability, which was classified as critical, has been found in linlinjava litemall up to 1.8.0. Affected by this issue is the function delete o…
Litemall
after 1.8.0
MEDIUM 6.7
CVE-2025-55149
Tiny-Scientist is a lightweight framework for automating the entire lifecycle of scientific research—from ideation to implementation, writing, and re…
Mitigation only
HIGH 8.7
CVE-2012-10048
Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() …
No fix yet
CRITICAL 9.8
CVE-2025-52913
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attacker…
Mitigation only
CRITICAL 9.8
CVE-2025-8356EPSS 15%
In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can lea…
Freeflow Core
Mitigation only
CRITICAL 9.1
CVE-2025-8729
A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is the function process_cert_file…
Lmeterx
Patch available
MEDIUM 6.5
CVE-2025-8749
Path Traversal vulnerability in API Endpoint in Mobile Industrial Robots (MiR) Software Versions prior to 3.0.0 on MiR Robots allows authenticated us…
Mitigation only
MEDIUM 6.5
CVE-2024-55401
An issue in 4C Strategies Exonaut before v22.4 allows attackers to execute a directory traversal.
Exonaut
21.6.2.1-1 / 22.4+
HIGH 8.7
CVE-2025-29865
: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.T…
Mitigation only
MEDIUM 5.4
CVE-2024-52885
The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (autho…
Mobile Access
Mitigation only
HIGH 7.1
CVE-2025-21015
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
Android
Mitigation only
MEDIUM 6.5
CVE-2025-54653
Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the v…
Harmonyos
Mitigation only
MEDIUM 5.5
CVE-2025-54652
Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the v…
Harmonyos
No fix yet
HIGH 7.5
CVE-2012-10034
ClanSphere 2011.3 is vulnerable to a local file inclusion (LFI) flaw due to improper handling of the cs_lang cookie parameter. The application fails …
Clansphere
No fix yet
HIGH 7.1
CVE-2012-10024
XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails …
Patch available
CRITICAL 9.8
CVE-2025-54802
pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path tra…
Pyload Ng
Patch available