Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-47118
Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying cra…
Patch available
HIGH 7.5
CVE-2026-48544
Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/libr…
Patch available
MEDIUM 6.5
CVE-2026-9035
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and I…
Aspera High Speed Transfer Endpoint
after 4.4.6
CRITICAL 9.8
CVE-2026-7524
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
Langflow
after 1.9.1
HIGH 7.5
CVE-2026-3366
IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote …
Infosphere Optim Test Data Fabrication
Mitigation only
CRITICAL 9.9
CVE-2026-42756
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Ludwig You QuickWebP – Compress / Optimize Imag…
Mitigation only
CRITICAL 9.9
CVE-2026-42757
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-igni…
Mitigation only
HIGH 8.6
CVE-2026-42737
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS vikboo…
Mitigation only
MEDIUM 5.8
CVE-2026-41009
When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 33…
Bosh
282.1.12+
MEDIUM 6.5
CVE-2026-44788
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in…
Sharpcompress
after 0.47.4
HIGH 8.2
CVE-2026-48126
Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --letsencrypt, which silently turn…
Mitigation only
HIGH 8.7
CVE-2026-43982
Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the ca…
Mitigation only
CRITICAL 9.8
CVE-2026-40383
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.5
CVE-2026-40384
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
Joomla\!
5.4.6 / 6.1.1+
HIGH 7.3
CVE-2026-9550
A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is so…
Mitigation only
CRITICAL 9.1
CVE-2026-42496
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() …
\
3.08+
MEDIUM 6.3
CVE-2026-9473
A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateIma…
Mitigation only
MEDIUM 6.3
CVE-2026-9472
A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_do…
Mitigation only
MEDIUM 6.3
CVE-2026-9468
A security flaw has been discovered in dazeb cline-mcp-memory-bank up to 55c81b9cf6c16700983c84dc4cdea3cafa19a75f. The affected element is the functi…
Mitigation only
HIGH 7.5
CVE-2018-25374
Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary fi…
No fix yet
HIGH 7.5
CVE-2018-25365
PCViewer vt1000 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting relative pat…
No fix yet
HIGH 8.3
CVE-2026-7766
Kenik Camera management Panel is vulnerable to Path Traversal vulnerability. An unauthenticated attacker can send GET request with arbitrary file pat…
Mitigation only
MEDIUM 6.5
CVE-2026-41863
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could all…
Spring Ai
1.1.7+
HIGH 8.5
CVE-2026-9489
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom p…
Mitigation only
MEDIUM 6.5
CVE-2026-9351
A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.16. This vulnerability affects the function _is_blocked_device of the f…
Mitigation only
MEDIUM 6.5
CVE-2026-36227
Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the…
Mitigation only
HIGH 7.5
CVE-2025-45145
Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system…
Mitigation only
CRITICAL 10.0
CVE-2026-34909 KEVEPSS 64%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi OS devices to access files on the underlying…
Unifi Os Server
5.0.8 / 5.1.12+
HIGH 7.7
CVE-2026-34911
A malicious actor with access to the network and low privileges could exploit a Path Traversal vulnerability found in UniFi OS devices to access file…
Unifi Os Server
5.0.8 / 5.1.12+
CRITICAL 9.8
CVE-2025-71210
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…
Apex One
14.0.0.14136 / 14.0.20315+