Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2019-25213
The Advanced Access Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read in versions up to, and including, 5.9.8.1 due t…
Advanced Access Manager
after 5.9.8.1
CRITICAL 9.1
CVE-2024-48914EPSS 60%
Vendure is an open-source headless commerce platform. Prior to versions 3.0.5 and 2.3.3, a vulnerability in Vendure's asset server plugin allows an a…
Patch available
MEDIUM 6.5
CVE-2024-9676
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda…
Openshift Container Platform
Patch available
HIGH 7.5
CVE-2024-9983
Enterprise Cloud Database from Ragic does not properly validate a specific page parameter, allowing unauthenticated remote attackers to exploit this …
Enterprise Cloud Database
2024-08-08+
HIGH 7.5
CVE-2024-46898
SHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability is exploite…
Shirasagi
1.19.1+
HIGH 7.8
CVE-2024-0129
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A succ…
Nemo
Mitigation only
HIGH 8.0
CVE-2024-45731
In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles…
Splunk
9.1.6 / 9.2.3+
CRITICAL 9.8
CVE-2024-9047EPSS 93%
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.…
Wordpress File Upload
4.24.12+
HIGH 7.5
CVE-2024-47877
Extract is aA Go library to extract archives in zip, tar.gz or tar.bz2 formats. A maliciously crafted archive may allow an attacker to create a symli…
Extract
4.0.0+
MEDIUM 6.5
CVE-2024-7514
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during t…
Mitigation only
HIGH 7.5
CVE-2024-47868
Gradio is an open-source Python package designed for quick prototyping. This is a **data validation vulnerability** affecting several Gradio componen…
Gradio
5.0.0+
MEDIUM 6.5
CVE-2024-47164
Gradio is an open-source Python package designed for quick prototyping. This vulnerability relates to the **bypass of directory traversal checks** wi…
Gradio
5.0.0+
MEDIUM 5.3
CVE-2024-47166
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a **one-level read path traversal** in the `/cust…
Gradio
4.44.0+
HIGH 7.2
CVE-2024-7037
In version v0.3.8 of open-webui/open-webui, the endpoint /api/pipelines/upload is vulnerable to arbitrary file write and delete due to unsanitized fi…
Open Webui
No fix yet
HIGH 8.5
CVE-2024-9575
Local File Inclusion vulnerability in pretix Widget WordPress plugin pretix-widget on Windows allows PHP Local File Inclusion. This issue affects pre…
Mitigation only
HIGH 7.1
CVE-2024-47191
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, …
Patch available
HIGH 7.2
CVE-2024-9381EPSS 16%
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
Endpoint Manager Cloud Services Appliance
5.0.2+
CRITICAL 9.8
CVE-2024-47010EPSS 38%
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
Avalanche
6.4.5+
HIGH 7.5
CVE-2024-47011EPSS 56%
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
Avalanche
6.4.5+
CRITICAL 9.8
CVE-2024-47009
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
Avalanche
6.4.5+
HIGH 7.5
CVE-2024-47948
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
Teamcity
2024.07.3+
HIGH 7.5
CVE-2024-47949EPSS 23%
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
Teamcity
2024.07.3+
MEDIUM 5.3
CVE-2024-47563
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly validate a file pat…
Sinec Security Monitor
4.9.0+
MEDIUM 6.5
CVE-2024-47818
Saltcorn is an extensible, open source, no-code database application builder. A logged-in user with any role can delete arbitrary files on the filesy…
Patch available
HIGH 8.8
CVE-2024-45291
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. It's possible for an attacker to construct an XLSX file that links im…
Phpspreadsheet
1.29.2 / 2.1.1+
CRITICAL 9.8
CVE-2024-47556
Pre-Auth RCE via Path Traversal
Freeflow Core
7.0.11+
CRITICAL 9.8
CVE-2024-47557
Pre-Auth RCE via Path Traversal
Freeflow Core
7.0.11+
HIGH 8.8
CVE-2024-47558
Authenticated RCE via Path Traversal
Freeflow Core
Mitigation only
HIGH 8.8
CVE-2024-47559
Authenticated RCE via Path Traversal
Freeflow Core
Mitigation only
CRITICAL 9.8
CVE-2024-46446
Mecha CMS 3.0.0 is vulnerable to Directory Traversal. An attacker can construct cookies and URIs that bypass user identity checks. Parameters can the…
Mecha
No fix yet