Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2025-2264EPSS 35%
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to downloa…
Sante Pacs Server
No fix yet
HIGH 8.1
CVE-2025-1785
The Download Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.08 via the 'wpdm_newfile' ac…
Download Manager
3.3.09+
HIGH 7.3
CVE-2025-27101
Opal is OBiBa’s core database application for biobanks or epidemiological studies. Prior to version 5.1.1, when copying any parent directory to a fol…
Patch available
HIGH 7.2
CVE-2024-55597
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to…
Fortiweb
7.4.6+
HIGH 8.1
CVE-2025-2193
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/dele…
Mrcms
No fix yet
MEDIUM 6.5
CVE-2025-27395
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly limit the scope …
Scalance Lpe9403 Firmware
4.0+
CRITICAL 9.8
CVE-2025-1661EPSS 56%
The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and includ…
Husky Products Filter Professional For Woocommerce
1.3.6.6+
CRITICAL 9.3
CVE-2025-27519
Cognita is a RAG (Retrieval Augmented Generation) Framework for building modular, open source applications for production by TrueFoundry. A path trav…
Patch available
HIGH 8.8
CVE-2024-12035
The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete(…
Mitigation only
HIGH 7.5
CVE-2024-10804
The Ultimate Video Player WordPress & WooCommerce Plugin plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includi…
Mitigation only
MEDIUM 5.9
CVE-2024-13894
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to path traversal.…
Mitigation only
MEDIUM 6.5
CVE-2024-13897
The Moving Media Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the generate_json_…
Mitigation only
HIGH 7.2
CVE-2025-24494
Path traversal may allow remote code execution using privileged account
(requires device admin account, cannot be performed by a regular user).
In …
Mitigation only
HIGH 7.5
CVE-2024-13471
The DesignThemes Core Features plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the dt_process_…
Mitigation only
HIGH 8.1
CVE-2025-1915
Improper Limitation of a Pathname to a Restricted Directory in DevTools in Google Chrome on Windows prior to 134.0.6998.35 allowed an attacker who co…
Chrome
134.0.6998.35+
CRITICAL 9.8
CVE-2024-8262
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Proliz Software OBS allows Path Traversal.
This issu…
Student Affairs Information System
24.0927+
HIGH 7.7
CVE-2025-26540
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in helloprint Helloprint helloprint allows Path Traversa…
Mitigation only
HIGH 7.5
CVE-2025-25162
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in kutu62 Sports Rankings and Lists sports-rankings-list…
Mitigation only
HIGH 8.6
CVE-2025-26534
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in helloprint Helloprint helloprint allows Path Traversa…
Mitigation only
CRITICAL 9.8
CVE-2025-27590EPSS 28%
In oxidized-web (aka Oxidized Web) before 0.15.0, the RANCID migration page allows an unauthenticated user to gain control over the Linux user accoun…
Oxidized Web
0.15.0+
HIGH 7.2
CVE-2024-13910
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient …
Mitigation only
MEDIUM 6.5
CVE-2025-27410
PwnDoc is a penetration test reporting application. Prior to version 1.2.0, the backup restore functionality is vulnerable to path traversal in the T…
Pwndoc
1.2.0+
MEDIUM 6.5
CVE-2025-0823
IBM Cognos Analytics 11.2.0 through 11.2.4 FP5 and 12.0.0 through 12.0.4 could allow a remote attacker to traverse directories on the system. An atta…
Cognos Analytics
11.2.4 / 12.0.4+
CRITICAL 9.8
CVE-2024-38292
In Extreme Networks XIQ-SE before 24.2.11, due to a missing access control check, a path traversal is possible, which may lead to privilege escalatio…
Xiq Se
24.2.11+
MEDIUM 5.3
CVE-2025-1743
A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textvi…
Mitigation only
HIGH 7.5
CVE-2025-25759
An issue in the component admin_template.php of SUCMS v1.0 allows attackers to execute a directory traversal and arbitrary file deletion via a crafte…
Sucms
Mitigation only
MEDIUM 6.5
CVE-2024-54169
IBM EntireX 11.1 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request …
Entirex
Mitigation only
HIGH 8.8
CVE-2025-1282
The Car Dealer Automotive WordPress Theme – Responsive theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path val…
Car Dealer Automotive
1.6.4+
MEDIUM 5.3
CVE-2025-25800
SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.
Seacms
No fix yet
MEDIUM 5.4
CVE-2022-25773
This advisory addresses a file placement vulnerability that could allow assets to be uploaded to unintended directories on the server.
* Improper…
Mautic
5.2.3+