Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.1
CVE-2026-73291
Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im…
No fix yet
MEDIUM 6.3
CVE-2026-67286
Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attac…
No fix yet
MEDIUM 5.3
CVE-2026-66381
A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.
No fix yet
CRITICAL 9.2
CVE-2026-67285
Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can p…
No fix yet
HIGH 8.1
CVE-2026-19594
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation thro…
No fix yet
MEDIUM 5.4
CVE-2026-63134
Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags…
No fix yet
MEDIUM 5.3
CVE-2026-73244
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/sr…
No fix yet
HIGH 7.8
CVE-2026-73234
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp co…
No fix yet
CRITICAL 9.8
CVE-2026-73034
DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s…
No fix yet
MEDIUM 5.0
CVE-2026-71475
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat…
No fix yet
HIGH 8.1
CVE-2026-19091
The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due t…
No fix yet
HIGH 8.1
CVE-2026-73225
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious FTP or SFTP …
No fix yet
HIGH 8.1
CVE-2026-73227
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious RDP server t…
No fix yet
HIGH 8.1
CVE-2026-73223
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.120, electerm allows a malicious SFTP server …
No fix yet
HIGH 7.5
CVE-2026-72713
XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitra…
No fix yet
HIGH 8.6
CVE-2026-48441
Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a…
Lightroom
15.5+
CRITICAL 9.8
CVE-2026-65768
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec…
Teams
1.0.0.2026133602+
HIGH 7.1
CVE-2026-48442
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could res…
C2pa
0.12.1 / 0.27.6+
MEDIUM 5.5
CVE-2026-48446
CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lea…
C2pa
0.12.1 / 0.27.6+
MEDIUM 5.4
CVE-2026-32677
Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivil…
No fix yet
HIGH 8.5
CVE-2026-73079
Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform …
No fix yet
HIGH 7.1
CVE-2026-18640
The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook …
No fix yet
MEDIUM 6.2
CVE-2026-72783
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContain…
No fix yet
HIGH 7.1
CVE-2026-72770
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated…
No fix yet
HIGH 7.5
CVE-2026-72602
A path traversal vulnerability in AsyncFuncAI deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to obtain directory listin…
No fix yet
MEDIUM 6.5
CVE-2026-72604
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server v…
No fix yet
MEDIUM 6.0
CVE-2026-33922
A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an i…
No fix yet
MEDIUM 5.9
CVE-2026-66777
SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…
No fix yet
HIGH 7.6
CVE-2026-44763
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using s…
No fix yet
HIGH 8.1
CVE-2026-73030
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize …
No fix yet