Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2024-49381
Plenti, a static site generator, has an arbitrary file deletion vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to …
Plenti
0.7.2+
HIGH 7.5
CVE-2024-10379
A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the fil…
Cdg
No fix yet
HIGH 7.8
CVE-2024-47027
In sm_mem_compat_get_vmm_obj of lib/sm/shared_mem.c, there is a possible arbitrary physical memory access due to improper input validation. This coul…
Android
Mitigation only
MEDIUM 5.3
CVE-2024-45842
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.
Unintended internal files m…
E Studio1058 Firmware
Mitigation only
HIGH 8.1
CVE-2024-10011
The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This make…
Buddypress
after 14.1.0
HIGH 7.5
CVE-2024-49359
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the API endpo…
Zimaos
1.2.5+
MEDIUM 5.3
CVE-2024-49760
OpenRefine is a free, open source tool for working with messy data. The load-language command expects a `lang` parameter from which it constructs the…
Openrefine
3.8.3+
HIGH 7.5
CVE-2024-48931
ZimaOS is a fork of CasaOS, an operating system for Zima devices and x86-64 systems with UEFI. In version 1.2.4 and all prior versions, the ZimaOS AP…
Zimaos
1.2.5+
CRITICAL 9.1
CVE-2024-47883
The OpenRefine fork of the MIT Simile Butterfly server is a modular web application framework. The Butterfly framework uses the `java.net.URL` class …
Butterfly
after 1.2.6
HIGH 8.8
CVE-2024-45262
An issue was discovered on certain GL-iNet devices, including MT6000, MT3000, MT2500, AXT1800, and AX1800 4.6.2. The params parameter in the call met…
Mt2500 Firmware
4.6.4+
HIGH 8.0
CVE-2024-10313
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal
vulnerability. When the software loads a malicious ‘ems' project
template f…
Mitigation only
MEDIUM 6.5
CVE-2024-20379
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center…
Firepower Management Center
Mitigation only
CRITICAL 9.8
CVE-2024-41717
Kieback & Peter's DDC4000 series is vulnerable to a path traversal vulnerability, which may allow an unauthenticated attacker to read files on the sy…
Mitigation only
HIGH 8.8
CVE-2024-35308
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: …
Pandora Fms
777.3+
CRITICAL 9.1
CVE-2024-41713 KEVEPSS 98%
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated att…
Micollab
after 9.8.1.201
HIGH 7.5
CVE-2024-49366
Nginx UI is a web user interface for the Nginx web server. Nginx UI v2.0.0-beta.35 and earlier gets the value from the json field without verificatio…
Nginx Ui
after 1.9.9-4
HIGH 7.5
CVE-2024-45309EPSS 25%
OneDev is a Git server with CI/CD, kanban, and packages. A vulnerability in versions prior to 11.0.9 allows unauthenticated users to read arbitrary f…
Onedev
11.0.9+
HIGH 7.8
CVE-2024-47742
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: Block path traversal
Most firmware names are hardcoded strings…
Debian Linux
4.19.323 / 5.4.285+
HIGH 7.5
CVE-2024-10200
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulner…
Administrative Management System
Mitigation only
CRITICAL 9.8
CVE-2024-49286
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV Events ssv-events allows PHP Loca…
Ssv Events
after 3.2.7
HIGH 7.5
CVE-2024-10100
A path traversal vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of the file parameter,…
Gpt Academic
No fix yet
HIGH 7.5
CVE-2024-49285
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Jeroen Berkvens SSV MailChimp ssv-mailchimp allows PH…
Mitigation only
HIGH 7.5
CVE-2024-49287
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in mh6webentwicklung PDF-Rechnungsverwaltung pdf-rechnun…
Mitigation only
HIGH 8.6
CVE-2024-49315
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager…
Mitigation only
HIGH 7.5
CVE-2024-49245
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in nahimsalami Ahime Image Printer ahime-image-printer.T…
Mitigation only
HIGH 8.8
CVE-2024-47637
Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache litespeed-cache allows Path Traversal.This issue affects LiteSpeed Ca…
Litespeed Cache
6.5.1+
HIGH 7.5
CVE-2024-47645
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Danish Ali Malik Top Bar – PopUps – by WPOptin wpopti…
Mitigation only
HIGH 7.5
CVE-2024-47351
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in The CSSIgniter Team MaxSlider maxslider allows Path T…
Mitigation only
HIGH 8.8
CVE-2024-45711EPSS 6%
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the…
Serv U
15.5+
HIGH 8.0
CVE-2020-36836
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a la…
Wp Fastest Cache
0.9.0.3+