Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-31359
A directory traversal vulnerability exists in the PVMP package unpacking functionality of Parallels Desktop for Mac version 20.2.2 (55879). This vuln…
Parallels Desktop
No fix yet
MEDIUM 5.3
CVE-2025-41428
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in TimeWorks 10.0 to 10.3. If exploited, arbitrary JSON f…
Mitigation only
HIGH 8.7
CVE-2025-48387
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the s…
Patch available
HIGH 7.5
CVE-2025-27956
Directory Traversal vulnerability in WebLaudos 24.2 (04) allows a remote attacker to obtain sensitive information via the id parameter.
Weblaudos
No fix yet
HIGH 7.2
CVE-2025-48940
MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attac…
Mybb
1.8.39+
CRITICAL 9.8
CVE-2025-37095
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
Storeonce System
4.3.11+
CRITICAL 9.1
CVE-2025-37094
A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
Storeonce System
4.3.11+
HIGH 7.5
CVE-2025-48957
AstrBot is a large language model chatbot and development framework. A path traversal vulnerability present in versions 3.4.4 through 3.5.12 may lead…
Astrbot
3.5.13+
MEDIUM 6.5
CVE-2025-33004
IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.
Planning Analytics Local
Mitigation only
CRITICAL 9.8
CVE-2025-5385
A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgfo…
Jeewms
after 2025-05-04
HIGH 7.2
CVE-2025-5381
A vulnerability, which was classified as problematic, was found in Yifang CMS up to 2.0.2. Affected is the function downloadFile of the file /api/Fil…
Yifang
after 2.0.2
MEDIUM 6.3
CVE-2025-5380
A vulnerability, which was classified as critical, has been found in ashinigit 天青一白 XueShengZhuSu 学生住宿管理系统 up to 4d3f0ada0e71482c1e51fd5f…
Mitigation only
HIGH 7.2
CVE-2025-4857
The Newsletters plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.9.9.9 via the 'file' parameter. Th…
Newsletters
4.10+
CRITICAL 9.1
CVE-2025-47952
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in T…
Traefik
2.11.25 / 3.4.1+
HIGH 8.8
CVE-2025-5328
A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sy…
Mccms
No fix yet
HIGH 7.5
CVE-2024-51453
IBM Sterling Secure Proxy 6.2.0.0 through 6.2.0.1 could allow a remote attacker to traverse directories on the system. An attacker could send a speci…
Sterling Secure Proxy
after 6.2.0.1
CRITICAL 9.8
CVE-2025-48744
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.
Pmb
8.0.1.2+
HIGH 7.5
CVE-2025-5161
A vulnerability classified as problematic was found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected by this vulnerability is the function oper…
Seccenter Smp 1114p02
after 20250513
HIGH 7.5
CVE-2025-5159
A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been rated as problematic. This issue affects the function Download of…
Seccenter Smp 1114p02
after 20250513
HIGH 7.5
CVE-2025-5160
A vulnerability classified as problematic has been found in H3C SecCenter SMP-E1114P02 up to 20250513. Affected is the function Download of the file …
Seccenter Smp 1114p02
after 20250513
HIGH 7.5
CVE-2025-5158
A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been declared as problematic. This vulnerability affects the function …
Seccenter Smp 1114p02
after 20250513
HIGH 7.5
CVE-2025-5157
A vulnerability was found in H3C SecCenter SMP-E1114P02 up to 20250513. It has been classified as critical. This affects the function fileContent of …
Seccenter Smp 1114p02
after 20250513
HIGH 7.5
CVE-2025-48273
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpjobportal WP Job Portal wp-job-portal allows Path T…
Wp Job Portal
2.3.3+
HIGH 7.5
CVE-2025-47603
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo belingogeo allows Path Traversal.T…
Mitigation only
HIGH 8.6
CVE-2025-47535
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom Product Variation opal-woo-cus…
Mitigation only
HIGH 8.6
CVE-2025-47492
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor F…
Mitigation only
HIGH 8.6
CVE-2025-47512
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainacan allows Path Traversal.This…
Mitigation only
MEDIUM 6.5
CVE-2025-46527
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likecoin allows Path Traversal.Thi…
Mitigation only
HIGH 7.7
CVE-2025-31053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-…
Mitigation only
HIGH 7.5
CVE-2025-3884
Cloudera Hue Ace Editor Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive in…
Hue
Mitigation only