Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-43440
A flaw was found in moodle. A local file may include risks when restoring block backups.
Moodle
4.1.12 / 4.2.9+
CRITICAL 9.3
CVE-2024-51990
jj, or Jujutsu, is a Git-compatible VCS written in rust. In affected versions specially crafted Git repositories can cause `jj` to write files outsid…
Mitigation only
MEDIUM 6.5
CVE-2024-51751
Gradio is an open-source Python package designed to enable quick builds of a demo or web application. If File or UploadButton components are used as …
Gradio
5.5.0+
MEDIUM 5.5
CVE-2024-20532
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To ex…
Identity Services Engine
3.1.0+
MEDIUM 5.5
CVE-2024-20527
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To ex…
Identity Services Engine
3.1.0+
HIGH 7.2
CVE-2024-20528
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operat…
Identity Services Engine
3.1.0+
MEDIUM 5.5
CVE-2024-20529
A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read and delete arbitrary files on an affected device. To ex…
Identity Services Engine
3.1.0+
MEDIUM 6.8
CVE-2024-47464
An authenticated Path Traversal vulnerability exists in Instant AOS-8 and AOS-10. Successful exploitation of this vulnerability allows an attacker to…
Mitigation only
HIGH 7.2
CVE-2024-47253
In 2N Access Commander versions 3.1.1.2 and prior, a Path Traversal vulnerability could allow an attacker with administrative privileges to write fil…
Access Commander
after 3.1.1.2
HIGH 7.1
CVE-2024-51127
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Hornetq
after 2.4.9
HIGH 8.8
CVE-2024-51582
Path Traversal: '.../...//' vulnerability in ThimPress WP Hotel Booking wp-hotel-booking allows PHP Local File Inclusion.This issue affects WP Hotel …
Wp Hotel Booking
after 2.1.4
HIGH 7.5
CVE-2024-10389
There exists a Path Traversal vulnerability in Safearchive on Platforms with Case-Insensitive Filesystems (e.g., NTFS). This allows Attackers to Writ…
Safearchive
2024-10-25+
MEDIUM 6.9
CVE-2024-51483
changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source…
Mitigation only
HIGH 7.7
CVE-2024-49770
`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does…
Patch available
HIGH 8.5
CVE-2024-37423
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Automattic Newspack Blocks allows Path Traversal.This…
Mitigation only
HIGH 7.7
CVE-2024-37108
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WishList Products WishList Member X allows Path Trave…
Mitigation only
HIGH 7.5
CVE-2024-39722
An issue was discovered in Ollama before 0.1.46. It exposes which files exist on the server on which it is deployed via path traversal in the api/pus…
Ollama
0.1.46+
CRITICAL 9.8
CVE-2024-39332
Webswing 23.2.2 allows remote attackers to modify client-side JavaScript code to achieve path traversal, likely leading to remote code execution via …
Webswing
No fix yet
MEDIUM 5.8
CVE-2024-10005
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP reques…
Consul
1.15.15 / 1.18.5+
HIGH 7.7
CVE-2024-48735
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal f…
Mitigation only
HIGH 7.5
CVE-2024-50508
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product…
Mitigation only
HIGH 8.6
CVE-2024-50509
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Chetan Khandla Woocommerce Product Design woo-product…
Mitigation only
HIGH 7.5
CVE-2024-7962
An arbitrary file read vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240628 due to insufficient validation when loading prompt templat…
Chuanhuchatgpt
Patch available
CRITICAL 9.1
CVE-2024-7774
A path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to s…
Langchain.js
Patch available
CRITICAL 9.8
CVE-2024-5982EPSS 31%
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling i…
Chuanhuchatgpt
20240918+
HIGH 7.8
CVE-2024-44255
A path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 14.7.1, ma…
Ipados
2.1 / 11.1+
HIGH 8.8
CVE-2024-50453
Relative Path Traversal vulnerability in webangon The Pack Elementor addons the-pack-addon allows PHP Local File Inclusion.This issue affects The Pac…
The Pack Elementor Addons
2.1.0+
MEDIUM 5.3
CVE-2024-49771
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. The patch for the historical vulnerabili…
Patch available
MEDIUM 5.3
CVE-2024-49766
Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //serv…
Werkzeug
3.0.6+
HIGH 8.8
CVE-2024-37847
An arbitrary file upload vulnerability in MangoOS before 5.1.4 and Mango API before 4.5.5 allows attackers to execute arbitrary code via a crafted fi…
Mango
4.5.5 / 5.1.4+