Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2026-52752
Ghidra before 12.0.2 contains a path traversal vulnerability in the extension installer that fails to validate ZIP entry names during extraction. Att…
Ghidra
12.0.2+
HIGH 7.8
CVE-2026-52755
Ghidra before 12.0.4 contains a path traversal vulnerability in the theme import functionality that allows attackers to write files outside the inten…
Ghidra
12.0.4+
MEDIUM 6.5
CVE-2026-52756
Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied …
Ghidra
after 12.1.2
MEDIUM 6.5
CVE-2026-24717
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator accoun…
Qts
5.2.9.3492+
HIGH 7.5
CVE-2026-44716
Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From version 0.0.90 to before version 1…
Pipecat
1.2.0+
HIGH 8.6
CVE-2026-46491
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module…
Patch available
MEDIUM 5.5
CVE-2026-34657
CAI Content Credentials versions [email protected], c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Direct…
C2pa
after 0.80.1
HIGH 8.8
CVE-2026-47932
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…
Coldfusion
Mitigation only
MEDIUM 5.3
CVE-2026-36726
An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete …
Mitigation only
HIGH 8.8
CVE-2026-36723
An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory tra…
Mitigation only
HIGH 7.7
CVE-2026-49957
Hermes WebUI before version 0.51.296 contains a workspace boundary bypass vulnerability that allows authenticated attackers to circumvent blocked-roo…
Patch available
HIGH 8.4
CVE-2026-45482
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attack…
Visual Studio Code
1.123.2+
HIGH 8.8
CVE-2026-45454
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execut…
Sharepoint Server
16.0.19725.20384+
HIGH 8.8
CVE-2026-32193
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to…
Azure Kubernetes Service
2026-02-13.5+
HIGH 7.8
CVE-2026-22926
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
Mitigation only
HIGH 7.5
CVE-2017-20248
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating t…
No fix yet
HIGH 7.5
CVE-2017-20250
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the a…
No fix yet
HIGH 7.1
CVE-2026-49742
Backend users with file download permissions were able to download files from the fallback storage of the file abstraction layer (FAL) via the Media …
Patch available
MEDIUM 6.5
CVE-2026-49818
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec…
Apache Airflow Providers Samba
4.12.6+
MEDIUM 5.4
CVE-2026-41972
Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.
No fix yet
MEDIUM 5.9
CVE-2026-41843
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
Affected versions:
Spring Framework 7.…
Spring Framework
5.3.49 / 6.1.28+
HIGH 8.1
CVE-2026-46484
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / author…
Mitigation only
MEDIUM 5.3
CVE-2026-46486
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise. Prior to versio…
Mitigation only
CRITICAL 9.4
CVE-2026-41448
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full…
Mitigation only
HIGH 8.8
CVE-2026-25559
OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arb…
Mitigation only
HIGH 7.5
CVE-2026-49233
Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This …
Routinator
0.15.2+
HIGH 8.7
CVE-2026-9506
This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remo…
Mitigation only
MEDIUM 6.2
CVE-2022-50953
WordPress Plugin admin-word-count-column 2.2 contains a local file read vulnerability that allows unauthenticated attackers to read arbitrary files b…
No fix yet
MEDIUM 6.3
CVE-2026-11470
A vulnerability has been found in hs-web hsweb-framework up to 5.0.1. The affected element is the function denied of the file hsweb-system/hsweb-syst…
Patch available
MEDIUM 5.4
CVE-2026-11467
A security vulnerability has been detected in jishenghua jshERP up to 3.6. This vulnerability affects the function addAccountHeadAndDetail of the fil…
Mitigation only