Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2025-71211
A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affecte…
Apex One
14.0.0.14136 / 14.0.20315+
CRITICAL 9.9
CVE-2026-4858
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which …
Mattermost Server
10.11.15 / 11.4.5+
HIGH 7.6
CVE-2026-44068
Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to…
Mitigation only
CRITICAL 9.4
CVE-2026-9129
A path traversal vulnerability exists in the Altium Enterprise Server Viewer StorageController due to improper handling of file path route parameters…
Mitigation only
CRITICAL 9.4
CVE-2026-9102
A path traversal vulnerability exists in the Altium Enterprise Server ComparisonService due to missing filename sanitization in the Gerber file uploa…
Mitigation only
HIGH 8.7
CVE-2026-39352
Frappe is a full-stack web application framework. Versions prior to 15.105.0 and 16.15.0 contain a possible Arbitrary File Read vulnerability via Pat…
Mitigation only
CRITICAL 9.4
CVE-2026-39405
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. In versions 2.50.0 and below, a user with cour…
Mitigation only
HIGH 7.5
CVE-2026-24208
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerabil…
Triton Inference Server
26.03+
HIGH 7.5
CVE-2026-24209
NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerabil…
Triton Inference Server
26.03+
MEDIUM 6.8
CVE-2026-35593
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 an…
Mitigation only
CRITICAL 9.8
CVE-2026-36829
An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session…
Mitigation only
HIGH 7.3
CVE-2025-70950
An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
Mitigation only
MEDIUM 5.9
CVE-2026-46724
The file indexer does not normalize the configured directory path. A backend user with permission to edit indexer configurations can index documents …
Mitigation only
MEDIUM 6.1
CVE-2026-31379
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-29220
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: befor…
Ofbiz
24.09.06+
CRITICAL 9.1
CVE-2026-45230
DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allow…
Patch available
HIGH 7.5
CVE-2026-29963
HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text …
Mailinspector
Mitigation only
MEDIUM 6.5
CVE-2026-20685
An attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved validation.…
Private Cloud Compute
5e290.3+
HIGH 7.5
CVE-2026-6381
The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowing authenticated users to per…
Mitigation only
MEDIUM 6.5
CVE-2026-8765
A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/ki…
Kilo Code
after 7.0.47
CRITICAL 9.1
CVE-2026-8757
A vulnerability was found in adenhq hive up to 0.11.0. This affects the function _read_events_tail of the file core/framework/server/routes_sessions.…
Hive
after 0.11.0
MEDIUM 6.3
CVE-2026-8754
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of …
Patch available
HIGH 7.3
CVE-2026-8755
A flaw has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The affected element is the function _get_all_models of…
Mitigation only
HIGH 7.3
CVE-2026-8756
A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c. The impacted element is the function generate_…
Mitigation only
HIGH 7.5
CVE-2018-25326
Google Drive for WordPress 2.2 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by injecting dir…
No fix yet
HIGH 7.5
CVE-2018-25325
Woocommerce CSV Importer 3.3.6 contains a path traversal vulnerability that allows any registered user to delete arbitrary files by submitting unesca…
No fix yet
HIGH 7.5
CVE-2021-47977
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attac…
No fix yet
HIGH 8.8
CVE-2021-47979
WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by ma…
No fix yet
HIGH 7.5
CVE-2021-47942
Home Assistant Community Store (HACS) prior to 1.10.0 contains a path traversal vulnerability that allows unauthenticated attackers to read sensitive…
Home Assistant Community Store
1.10.0+
HIGH 8.1
CVE-2026-44565
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the…
Open Webui
0.6.10+