Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.3
CVE-2025-22240
Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated inp…
Mitigation only
MEDIUM 5.6
CVE-2025-22241
File contents overwrite the VirtKey class is called when “on-demand pillar” data is requested and uses un-validated input to create paths to the “pki…
Mitigation only
HIGH 8.8
CVE-2025-4613
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution b…
Web Designer
16.3.0.0407+
MEDIUM 6.1
CVE-2025-40592
A vulnerability has been identified in Mendix Studio Pro 10 (All versions < V10.23.0), Mendix Studio Pro 10.12 (All versions < V10.12.17), Mendix Stu…
Mitigation only
HIGH 7.8
CVE-2025-47176
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
365 Apps
No fix yet
MEDIUM 5.4
CVE-2024-57189
In Erxes <1.6.2, an authenticated attacker can write to arbitrary files on the system using a Path Traversal vulnerability in the importHistoriesCrea…
Erxes
1.6.2+
MEDIUM 5.4
CVE-2024-57186
In Erxes <1.6.2, an unauthenticated attacker can read arbitrary files from the system using a Path Traversal vulnerability in the /read-file endpoint…
Erxes
1.6.2+
HIGH 7.7
CVE-2025-37100
A vulnerability in the APIs of HPE Aruba Networking Private 5G Core could potentially expose sensitive information to unauthorized users.
A successf…
Mitigation only
HIGH 7.2
CVE-2025-5740
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file writes wh…
Mitigation only
HIGH 7.6
CVE-2025-42977
SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privil…
Mitigation only
MEDIUM 6.5
CVE-2025-49138
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.0, an authenticated Local File Inclusion (LFI) …
Haxcms Php
11.0.0+
CRITICAL 9.1
CVE-2025-48267
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue …
Wp Pipes
1.4.3+
HIGH 7.5
CVE-2025-48130
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks spice-blocks allows Path Tra…
Mitigation only
HIGH 7.5
CVE-2025-48124
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Spreadsheet Price Changer for WooC…
Mitigation only
MEDIUM 6.5
CVE-2025-47511
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in info@welcart Welcart e-Commerce usc-e-shop allows Pat…
Welcart E Commerce
2.11.14+
HIGH 8.1
CVE-2025-39473
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WebGeniusLab Seofy Core seofy-core allows PHP Local F…
Mitigation only
HIGH 7.5
CVE-2025-31635
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LambertGroup CLEVER lbg-audio11-html5-shoutcast_histo…
Mitigation only
HIGH 7.5
CVE-2025-31050
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appthaplugins Apptha Slider Gallery apptha-slider-gal…
Mitigation only
HIGH 8.8
CVE-2025-3485
Allegra extractFileFromZip Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary c…
Allegra
8.1.2+
MEDIUM 6.5
CVE-2025-33035
A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vuln…
File Station
5.5.6.4847+
HIGH 8.1
CVE-2025-3055
The WP User Frontend Pro plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_avatar_…
Mitigation only
MEDIUM 6.7
CVE-2025-20277
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on …
Unified Contact Center Express
Mitigation only
MEDIUM 5.3
CVE-2025-20259
Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delet…
Thousandeyes Endpoint Agent
2.3.3+
HIGH 7.5
CVE-2025-5545
A vulnerability classified as problematic has been found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. This affects the fun…
Oa System
No fix yet
HIGH 7.5
CVE-2025-5544
A vulnerability was found in aaluoxiang oa_system up to 5b445a6227b51cee287bd0c7c33ed94b801a82a5. It has been rated as problematic. Affected by this …
Oa System
No fix yet
CRITICAL 9.8
CVE-2025-5509
A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part of the file /api/file/upload…
Shiyi Blog
after 1.2.1
MEDIUM 5.3
CVE-2024-12718
Allows modifying some file metadata (e.g. last modified) with filter="data" or file permissions (chmod) with filter="tar" of files outside the extrac…
Patch available
HIGH 7.5
CVE-2025-4138
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me…
Patch available
HIGH 7.5
CVE-2025-4330
Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file me…
Patch available
CRITICAL 9.4
CVE-2025-4517
Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data".
You are affected by this vulnerability if…
Patch available