Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-45309
AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio frame…
Asyncssh
2.23.0+
HIGH 8.6
CVE-2026-15343
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updat…
No fix yet
HIGH 8.8
CVE-2026-62229
OpenClaw before 2026.5.18 contain an authorization bypass vulnerability in exec allowlist glob matching that allows lower-trust callers to execute ac…
Openclaw
2026.5.18+
HIGH 7.5
CVE-2026-39359
Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.0.0 through 4.10.3 and 4.11.0 through 4.1…
Wazuh
4.10.4 / 4.14.5+
HIGH 8.8
CVE-2026-44177
Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user…
No fix yet
HIGH 8.6
CVE-2026-44023
Docling Core defines core data types and transformations for the document processing application Docling. In versions 1.5.0 and above, prior to 2.74.…
Docling Core
2.74.1+
HIGH 7.3
CVE-2024-32386
Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive in…
No fix yet
HIGH 8.7
CVE-2026-55629
Whistle is an HTTP, HTTP2, HTTPS, and WebSocket debugging proxy. Prior to 2.10.3, lib/service/service.js handles GET /cgi-bin/temp/get by reading req…
Patch available
MEDIUM 5.9
CVE-2026-53535
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a …
Patch available
HIGH 7.1
CVE-2026-46336
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 unti…
Patch available
CRITICAL 9.1
CVE-2026-45568
zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an ab…
Zrok
2.0.3+
HIGH 7.5
CVE-2026-45576
zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or z…
Zrok
2.0.3+
HIGH 7.3
CVE-2026-13103
A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local au…
No fix yet
MEDIUM 6.5
CVE-2025-45870
LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated …
No fix yet
CRITICAL 9.3
CVE-2026-59864
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`…
Patch available
CRITICAL 9.3
CVE-2026-59866
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa…
Patch available
HIGH 7.1
CVE-2026-59867
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs …
Patch available
HIGH 7.5
CVE-2026-53598
Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty fron…
Patch available
HIGH 7.0
CVE-2026-59863
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configurat…
Patch available
HIGH 7.1
CVE-2026-52890
Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /att…
Patch available
HIGH 8.5
CVE-2026-45419
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template saves call TemplateManageService#save, StaticRes…
Patch available
HIGH 8.3
CVE-2026-45533
DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase export-center deletion can accept path traversal sequence…
Patch available
MEDIUM 5.4
CVE-2026-26032
The PackagerResolver of Apache Ivy is able to download online
artifacts and to (re)package them in a format defined by a
packager.xml file. This repa…
Ivy
2.6.0+
HIGH 7.5
CVE-2026-12997
The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_file…
Mitigation only
HIGH 7.2
CVE-2026-20297
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, 9.4.13, and 9.3.14, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10…
Splunk
9.3.14 / 9.4.13+
MEDIUM 5.5
CVE-2026-20146
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attac…
Identity Services Engine Passive Identity Connector
3.3.0+
MEDIUM 6.8
CVE-2026-62843
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 …
Patch available
MEDIUM 6.4
CVE-2026-60062
The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secur…
Nginx Agent
2.22.2 / 2.46.7+
CRITICAL 9.1
CVE-2026-43637
Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache dire…
Patch available
HIGH 8.1
CVE-2026-61443
PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containmen…
Mitigation only