Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.3
CVE-2026-19758
A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of…
No fix yet
HIGH 7.3
CVE-2026-19757
A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the co…
No fix yet
MEDIUM 6.3
CVE-2026-19756
A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the compo…
No fix yet
HIGH 8.2
CVE-2026-73658
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…
No fix yet
HIGH 8.1
CVE-2026-73659
Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app…
No fix yet
CRITICAL 9.1
CVE-2026-72850
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p…
No fix yet
HIGH 7.5
CVE-2026-17473
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a res…
No fix yet
MEDIUM 6.9
CVE-2026-45774
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profil…
No fix yet
HIGH 7.1
CVE-2026-48099
WsgiDAV is a generic and extendable WebDAV server based on WSGI. WsgiDAV 4.3.3 and prior can allow a WebDAV request path containing an encoded parent…
No fix yet
HIGH 8.8
CVE-2026-16908
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vul…
I
No fix yet
CRITICAL 9.4
CVE-2026-73653
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…
No fix yet
HIGH 8.2
CVE-2026-13048
Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon …
No fix yet
HIGH 7.6
CVE-2026-73509
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch…
No fix yet
HIGH 8.1
CVE-2026-70460
rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with…
No fix yet
HIGH 7.7
CVE-2026-65582
Subscriber Arbitrary File Download in AI Hub <= 1.3.10 versions.
No fix yet
HIGH 7.5
CVE-2026-61980
Unauthenticated Arbitrary File Download in OMGF Pro <= 5.2.7 versions.
No fix yet
HIGH 7.4
CVE-2026-28189
Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.4 versions.
No fix yet
HIGH 8.1
CVE-2026-73620
GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe opt…
No fix yet
HIGH 7.7
CVE-2026-73498
MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment pa…
No fix yet
MEDIUM 6.5
CVE-2026-64826
rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized di…
No fix yet
CRITICAL 9.9
CVE-2026-66898
A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing …
No fix yet
HIGH 8.8
CVE-2026-13105
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.
I Access Client Solutions
No fix yet
HIGH 8.8
CVE-2026-13622
A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside…
No fix yet
HIGH 8.5
CVE-2026-16033
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image me…
No fix yet
CRITICAL 9.0
CVE-2026-73407
Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials …
No fix yet
HIGH 7.6
CVE-2026-73327
Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a craft…
No fix yet
MEDIUM 6.5
CVE-2026-17266
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to …
I
after 7.6
HIGH 7.1
CVE-2026-17094
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal…
I
Fix unknown
MEDIUM 5.3
CVE-2026-66384
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
No fix yet
MEDIUM 6.8
CVE-2026-65939
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within …
No fix yet