CVE-2024-48248High· 8.6▾ Abyssal⚠ Exploited in the wildPoC availableNAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 47.3 · likelihood 18.9 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Apr 9, 2025
Last analysed / modified upstream
94%
1 GitHub repo · Nuclei ×1 (last check)
Added to the CISA catalog on Mar 19, 2025. Federal remediation due Apr 9, 2025. View catalog ↗
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext credentials).
backup_&_replication_director < 11.0.0.88174Upgrade past the affected range:
backup_&_replication_director 11.0.0.88174Connected by shared product, vendor, weakness, or advisory.
CVE-2018-20250High· 7.8In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll)
CVE-2026-0846High· 8.6Arbitrary File Read via Absolute Path Input in nltk.util.filestring()
CVE-2026-47243Critical· 9.2Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers
CVE-2026-89009Critical· 9.1WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…
CVE-2026-55062High· 8.4uniget is a universal installer and updater for (container) tools
CVE-2025-70820Low· 3.5Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.