Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.1
CVE-2024-7776
A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite…
Onnx
after 1.16.1
HIGH 7.2
CVE-2024-7034
In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames.…
Open Webui
No fix yet
HIGH 7.5
CVE-2024-6851
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleti…
Aim
No fix yet
CRITICAL 9.1
CVE-2024-5752
A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a…
Patch available
HIGH 7.5
CVE-2024-12866
A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files…
Qanything
No fix yet
MEDIUM 5.3
CVE-2024-12217
A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_…
Mitigation only
HIGH 7.5
CVE-2024-12065
A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the s…
Llava
No fix yet
MEDIUM 6.5
CVE-2024-11037
A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection…
Gpt Academic
No fix yet
CRITICAL 9.8
CVE-2024-10902
In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This …
Db Gpt
No fix yet
MEDIUM 6.5
CVE-2024-10948
A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files …
Gpt Academic
No fix yet
HIGH 8.2
CVE-2024-10830
A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability all…
Db Gpt
No fix yet
MEDIUM 6.5
CVE-2024-10707
gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, wh…
Chuanhuchatgpt
No fix yet
HIGH 7.2
CVE-2024-10513
A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to …
Anythingllm
1.2.2+
CRITICAL 9.1
CVE-2024-10361
An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulner…
Librechat
Patch available
CRITICAL 9.8
CVE-2025-2505
The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 via the 'lang' parameter. Thi…
Mitigation only
HIGH 8.8
CVE-2025-1770
The Event Manager, Events Calendar, Tickets, Registrations – Eventin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to…
Eventin
4.0.25+
CRITICAL 9.8
CVE-2025-27782
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.py. This issue may lead to wri…
Applio
after 3.2.8-bugfix
CRITICAL 9.8
CVE-2025-27783
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. This issue may lead to writing…
Applio
after 3.2.8-bugfix
HIGH 7.5
CVE-2025-27785
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file read in train.py's `export_index` function. This …
Applio
after 3.2.8-bugfix
CRITICAL 9.1
CVE-2025-27786
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. `output_tts_path` in tts.py t…
Applio
after 3.2.8-bugfix
HIGH 7.5
CVE-2025-27787
Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to denial of service (DoS) in restart.py. `model_name` in train.py …
Applio
after 3.2.8-bugfix
MEDIUM 6.5
CVE-2024-57170
SOPlanning 1.53.00 is vulnerable to a directory traversal issue in /process/upload.php. The "fichier_to_delete" parameter allows authenticated attack…
Soplanning
No fix yet
HIGH 8.8
CVE-2025-2449EPSS 32%
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create a…
Flexlogger
Mitigation only
HIGH 7.5
CVE-2025-2493
Path Traversal vulnerability in Softdial Contact Center of Sytel Ltd. This vulnerability allows an attacker to manipulate the ‘id’ parameter of the ‘…
Softdial Contact Center
Mitigation only
MEDIUM 6.6
CVE-2025-0694
Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
Mitigation only
MEDIUM 5.3
CVE-2024-8510
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed.
Thi…
N Central
2024.6+
HIGH 7.5
CVE-2025-25684
A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the dev…
Mitigation only
HIGH 7.5
CVE-2025-25685
An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding…
Mitigation only
HIGH 7.3
CVE-2025-29787
`zip` is a zip library for rust which supports reading and writing of simple ZIP files. In the archive extraction routine of affected versions of the…
Patch available
CRITICAL 9.8
CVE-2025-2363
A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/…
Vblog
Mitigation only