Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2026-6968
Incomplete path traversal fixes in awslabs/tough before tough-v0.22.0 allow remote authenticated users with delegated signing authority to write file…
Tough
0.15.0 / 0.22.0+
HIGH 8.4
CVE-2026-41433
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From 0.4.0 to before 0.8.0, a flaw in the Java …
Opentelemetry Ebpf Instrumentation
0.8.0+
HIGH 7.1
CVE-2026-41894
SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePat…
Patch available
HIGH 7.6
CVE-2026-41419
4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board…
Mitigation only
HIGH 8.7
CVE-2026-41140
Poetry is a dependency manager for Python. Prior to 2.3.4, the extractall() function in src/poetry/utils/helpers.py:410-426 extracts sdist tarballs w…
Mitigation only
CRITICAL 9.8
CVE-2026-33076
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the haproxy_section_save interface p…
Roxy Wi
8.2.6.4+
HIGH 7.5
CVE-2026-33077
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to version 8.2.6.4, the oldconfig parameter in the hapro…
Roxy Wi
8.2.6.4+
MEDIUM 6.1
CVE-2026-29050
melange allows users to build apk packages using declarative pipelines. Starting in version 0.32.0 and prior to version 0.43.4, an attacker who can i…
Melange
0.43.4+
HIGH 7.1
CVE-2026-6940
radare2 prior to 6.1.4 contains a path traversal vulnerability in project deletion that allows local attackers to recursively delete arbitrary direct…
Radare2
6.1.4+
HIGH 7.8
CVE-2026-6941
radare2 prior to 6.1.4 contains a path traversal vulnerability in its project notes handling that allows attackers to read or write files outside the…
Radare2
6.1.4+
HIGH 7.5
CVE-2026-41205
Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with /…
Mako
1.3.11+
HIGH 7.5
CVE-2026-6903
The LabOne Web Server, backing the LabOne User Interface, contains insufficient input validation in its file access functionality. An unauthenticated…
Mitigation only
CRITICAL 10.0
CVE-2026-41211
Vite+ is a unified toolchain and entry point for web development. Prior to version 0.1.17, `downloadPackageManager()` accepts an untrusted `version` …
Vite\+
0.1.17+
HIGH 7.5
CVE-2026-41180
PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.4.3, the upload PATCH flow under `/files/:uploadId` validates th…
Patch available
HIGH 7.5
CVE-2026-40062
A path Traversal vulnerability exists in Ziostation2 v2.9.8.7 and earlier. A remote unauthenticated attacker may get sensitive information on the ope…
Ziostation2
after 2.9.8.7
CRITICAL 9.1
CVE-2026-33656
EspoCRM is an open source customer relationship management application. Prior to version 9.3.4, EspoCRM's built-in formula scripting engine allowing …
Espocrm
9.3.4+
HIGH 7.1
CVE-2026-34414
Xerte Online Toolkits versions 3.15 and earlier contain a relative path traversal vulnerability in the elFinder connector endpoint at /editor/elfinde…
Patch available
MEDIUM 5.6
CVE-2026-35363
A vulnerability in the rm utility of uutils coreutils allows the bypass of safeguard mechanisms intended to protect the current directory. While the …
Coreutils
No fix yet
HIGH 7.3
CVE-2026-35338
A vulnerability in the chmod utility of uutils coreutils allows users to bypass the --preserve-root safety mechanism. The implementation only validat…
Coreutils
0.6.0+
CRITICAL 9.1
CVE-2026-32885
DDEV is an open-source tool for running local web development environments for PHP and Node.js. Versions prior to 1.25.2 have unsanitized extraction …
Ddev
1.25.2+
HIGH 7.1
CVE-2026-6855
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…
Instructlab
Mitigation only
MEDIUM 6.5
CVE-2026-4280
The Breaking News WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3. This is due to the brnwp_a…
Mitigation only
HIGH 8.1
CVE-2026-41058
WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not a…
Avideo
after 29.0
MEDIUM 6.5
CVE-2026-41062
WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVi…
Avideo
after 29.0
HIGH 8.1
CVE-2026-6832
Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete file…
Hermes Web Ui
0.50.32+
MEDIUM 6.3
CVE-2026-6829
nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an …
Patch available
MEDIUM 5.4
CVE-2026-40923
Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.2, 1.3…
Tekton Pipelines
1.11.1+
MEDIUM 6.5
CVE-2026-40909
WWBN AVideo is an open source video platform. In versions 29.0 and prior, the locale save endpoint (`locale/save.php`) constructs a file path by dire…
Avideo
after 29.0
HIGH 8.8
CVE-2026-40876
goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.6, goshs contains an SFTP root escape caused by prefix-based path validation. An authe…
Goshs
2.0.0+
CRITICAL 9.1
CVE-2026-41193
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives…
Patch available