Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-65689
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that all…
Standalone Report Designer
14.1.12+
HIGH 8.8
CVE-2026-65690
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that all…
Standalone Report Designer
14.1.12+
CRITICAL 9.8
CVE-2026-65687
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows…
Standalone Report Designer
14.1.12+
MEDIUM 6.5
CVE-2026-65607
SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serv…
No fix yet
HIGH 7.7
CVE-2026-59542
Subscriber Arbitrary File Deletion in Kali Forms <= 2.4.18 versions.
No fix yet
CRITICAL 10.0
CVE-2026-59555
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.
No fix yet
HIGH 7.1
CVE-2026-57696
Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions.
No fix yet
MEDIUM 5.3
CVE-2026-57716
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.
No fix yet
HIGH 7.5
CVE-2026-65754
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the s…
No fix yet
MEDIUM 6.5
CVE-2026-64872
Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directo…
No fix yet
CRITICAL 9.8
CVE-2026-65431
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation…
Mitigation only
MEDIUM 6.2
CVE-2026-65712
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site …
No fix yet
MEDIUM 6.5
CVE-2026-65713
Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories.
No fix yet
MEDIUM 6.5
CVE-2026-16078
The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including…
No fix yet
HIGH 7.5
CVE-2026-15074
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This …
Fastify Static
10.1.1+
MEDIUM 5.3
CVE-2026-16653
A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of…
No fix yet
HIGH 7.8
CVE-2026-14985
The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to…
No fix yet
HIGH 8.1
CVE-2026-13186
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploite…
Telerik Ui For Asp.net Ajax
2026.2.708+
MEDIUM 5.3
CVE-2026-65600
Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathReg…
Traefik
2.11.52 / 3.6.23+
MEDIUM 6.6
CVE-2026-44192
A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to ma…
No fix yet
HIGH 8.4
CVE-2026-56844
A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain roo…
No fix yet
CRITICAL 9.1
CVE-2026-47731
The AMMOS Instrument Toolkit (Formerly the Bespoke Links to Instruments for Surface and Space (BLISS)) is a Python-based software suite developed to …
No fix yet
HIGH 7.5
CVE-2026-30633
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted path value to the get_doc and update_doc tools.
No fix yet
HIGH 7.8
CVE-2026-50757
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-…
No fix yet
HIGH 7.5
CVE-2026-30632
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
No fix yet
HIGH 7.2
CVE-2026-63454
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary fi…
Arubaos Cx
after 10.18.0001
MEDIUM 6.9
CVE-2026-47425
Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_c…
No fix yet
HIGH 7.1
CVE-2026-47397
PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled c…
No fix yet
HIGH 8.7
CVE-2026-15724
In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal …
No fix yet
HIGH 7.5
CVE-2026-15789
A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The cli…
Buildkit
0.31.2+