VYPR

OneCommander

by Milos Paripovic

CVEs (2)

  • CVE-2025-63371HigNov 19, 2025
    risk 0.49cvss 7.5epss 0.01

    Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file processing component, specifically in the functionality responsible for extracting and handling ZIP archive contents.

  • CVE-2025-50324HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.