Known Vulnerabilities for Unzip by Unzip Project
Listed below are 10 of the newest known vulnerabilities associated with "Unzip" by "Unzip Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40180 json | Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to 2.16.0 ... | Not Provided | 2026-04-10 | 2026-04-13 |
| CVE-2026-32885 json | DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have... | Not Provided | 2026-04-22 | 2026-04-22 |
| CVE-2025-70952 json | pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zi... | Not Provided | 2026-03-25 | 2026-03-28 |
| CVE-2025-4748 json | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (stdlib modules) a... | Not Provided | 2025-06-16 | 2026-04-06 |
| CVE-2024-36057 json | Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code executi... | Not Provided | 2026-04-07 | 2026-04-09 |
| CVE-2022-0530 json | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a ... | 5.5 - MEDIUM | 2022-02-09 | 2023-11-09 |
| CVE-2022-0529 json | A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a ... | 5.5 - MEDIUM | 2022-02-09 | 2023-11-09 |
| CVE-2021-4217 json | A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null poi... | 3.3 - LOW | 2022-08-24 | 2022-11-29 |
| CVE-2020-36561 json | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) out... | 9.1 - CRITICAL | 2022-12-27 | 2023-06-08 |
| CVE-2019-25471 json | FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ... | 9.1 - CRITICAL | 2026-03-11 | 2026-04-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Unzip Project | Unzip | 6.0 | |||
| Application | Unzip Project | Unzip | 5.52 | |||
| Application | Unzip Project | Unzip | 5.51 |