All previously released versions of Sprockets (4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower), the software that powers the Rails asset pipeline, contain a directory traversal vulnerability.
All users running an affected release should either upgrade or use one of the work arounds immediately.
Rails Asset Pipeline Directory Traversal Vulnerability (CVE-2018-3760)
Do not respond to http requests asking for a `file://`
WordPress Plugin Aspose Cloud eBook Generator Arbitrary File Download (1.0)
WordPress Plugin Duplicator-WordPress Migration Arbitrary File Disclosure (0.3.0)
ColdFusion directory traversal
WordPress Plugin Download Shortcode Arbitrary File Disclosure (0.1)
WordPress Plugin Ultimate Member-User Profile, User Registration, Login & Membership Multiple Vulnerabilities (1.3.88)