Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-7521
Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin…
Mattermost Server
10.11.21 / 11.6.6+
HIGH 7.2
CVE-2026-16585
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for WordPress is vulnerable to arbitrary file deletion due to in…
No fix yet
HIGH 7.5
CVE-2026-14490
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to…
No fix yet
HIGH 7.5
CVE-2026-17524
Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extractio…
No fix yet
CRITICAL 9.8
CVE-2026-64731
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be a…
macOS
15.7.8 / 26.6+
CRITICAL 9.3
CVE-2026-64740
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10…
Ipados
14.8.8 / 15.7.8+
HIGH 8.2
CVE-2026-43772
A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26…
macOS
14.8.8 / 15.7.8+
HIGH 7.8
CVE-2026-43749
A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS So…
macOS
14.8.8 / 15.7.8+
HIGH 7.8
CVE-2026-43723
A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS …
Ipados
14.8.8 / 15.7.8+
HIGH 8.8
CVE-2026-65921
A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build arti…
Artifactory
7.111.18 / 7.117.25+
CRITICAL 9.1
CVE-2026-45623
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. In versions 8.5.…
Postcss
8.5.12+
HIGH 8.6
CVE-2026-66397
phpMyFAQ before 4.1.6 fails to validate path traversal sequences in the existing_image field during category updates, allowing authenticated attacker…
No fix yet
HIGH 7.5
CVE-2026-66050
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the…
No fix yet
MEDIUM 6.8
CVE-2026-65436
Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.
No fix yet
HIGH 8.3
CVE-2026-65878
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a…
No fix yet
MEDIUM 5.3
CVE-2026-17514
A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract…
No fix yet
MEDIUM 6.9
CVE-2026-65765
Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Commander 1.0.0-6.1.1 - Improper limitation of paths for save and download action…
No fix yet
MEDIUM 6.5
CVE-2026-14955
The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.7.7…
No fix yet
MEDIUM 5.3
CVE-2026-66004
BlenderMCP before commit 30a3308 contains a path traversal vulnerability in the download_polyhaven_asset method that allows attackers to write arbitr…
No fix yet
MEDIUM 6.5
CVE-2026-66007
Datasets through 5.0.0, fixed in commit f989ef9, contains a path traversal vulnerability in folder-based dataset builders where the file_name metadat…
Datasets
No fix yet
MEDIUM 6.5
CVE-2026-16767
A vulnerability was detected in Ne-Lexa php-zip up to 4.0.2. This affects the function ZipFile::extractTo of the file src/ZipFile.php of the componen…
No fix yet
HIGH 7.5
CVE-2026-65694
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to r…
No fix yet
CRITICAL 9.3
CVE-2026-47669
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`…
No fix yet
HIGH 7.5
CVE-2026-65919
Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoint…
No fix yet
CRITICAL 9.8
CVE-2026-65700
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,…
No fix yet
CRITICAL 9.1
CVE-2026-65701
SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una…
No fix yet
HIGH 8.6
CVE-2026-65702
Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated re…
No fix yet
MEDIUM 5.3
CVE-2026-65698
Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrar…
No fix yet
MEDIUM 6.8
CVE-2026-65695
Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filen…
No fix yet
CRITICAL 9.8
CVE-2026-65688
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allow…
Standalone Report Designer
14.1.12+