Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.6
CVE-2026-33581
OpenClaw before 2026.3.24 contains a sandbox bypass vulnerability in the message tool that allows attackers to read arbitrary local files by using me…
Openclaw
2026.3.24+
HIGH 7.6
CVE-2026-29870
A directory traversal vulnerability in the agentic-context-engine project versions up to 0.7.1 allows arbitrary file writes via the checkpoint_dir pa…
Mitigation only
CRITICAL 9.1
CVE-2025-10559
A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Rele…
3dexperience
Mitigation only
HIGH 7.5
CVE-2026-34070
LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.load…
Langchain Core
1.2.22+
MEDIUM 6.5
CVE-2026-32727
SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.7, the Enforcer is vulnerable to a path traversal attack wh…
Scitokens Library
1.9.7+
HIGH 7.2
CVE-2026-30940
baserCMS is a website development framework. Prior to version 5.2.3, a path traversal vulnerability exists in the theme file management API (/baser/a…
Basercms
5.2.3+
HIGH 7.5
CVE-2026-27018
Gotenberg is an API for converting document formats. Prior to version 8.29.0, the fix introduced for CVE-2024-21527 can be bypassed using mixed-case …
Gotenberg
8.29.0+
MEDIUM 6.5
CVE-2026-33027
Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.4, the nginx-ui configuration improperly handles URL-encoded traversa…
Nginx Ui
2.3.4+
CRITICAL 10.0
CVE-2025-15036
A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artifact_cache.py` file of the mlf…
Mlflow
3.9.0+
MEDIUM 5.3
CVE-2026-5014
A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log/ of the component Wildcard H…
Mitigation only
MEDIUM 5.3
CVE-2026-5013
A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key. The manipulation of the arg…
Mitigation only
MEDIUM 6.3
CVE-2026-4999
A security vulnerability has been detected in z-9527 admin up to 72aaf2dd05cf4ec2e98f390668b41e128eec5ad2. This issue affects the function uploadFile…
Mitigation only
MEDIUM 5.3
CVE-2026-4997
A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql…
Mitigation only
HIGH 8.4
CVE-2016-20048
iSelect 1.4.0-2+b1 contains a local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized val…
No fix yet
HIGH 8.4
CVE-2016-20040
TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application o…
No fix yet
HIGH 8.4
CVE-2016-20041
Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an …
No fix yet
MEDIUM 6.5
CVE-2026-33989
Mobile Next is an MCP server for mobile development and automation. Prior to version 0.0.49, the `@mobilenext/mobile-mcp` server contains a Path Trav…
Mobile Mcp
0.0.49+
HIGH 8.8
CVE-2026-5027EPSS 33%
The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arb…
Langflow
1.9.0+
HIGH 7.5
CVE-2026-33748
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insuf…
Buildkit
0.28.1+
HIGH 7.5
CVE-2026-29871
A path traversal vulnerability exists in the awesome-llm-apps project in commit e46690f99c3f08be80a9877fab52acacf7ab8251 (2026-01-19) in the Beifong …
Awesome Llm Apps
2026-01-19+
CRITICAL 9.8
CVE-2026-4619
Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
Aterm Wx3600hp Firmware
1.5.3+
MEDIUM 5.3
CVE-2026-0394
When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or slash has been added to allowe…
Dovecot
2.4.0 / 3.1.0+
CRITICAL 9.8
CVE-2026-33747
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when …
Buildkit
0.28.1+
CRITICAL 9.6
CVE-2026-33945
Incus is a system container and virtual machine manager. Incus instances have an option to provide credentials to systemd in the guest. For container…
Incus
6.23.0+
HIGH 8.8
CVE-2026-33686
Sharp is a content management framework built for Laravel as a package. Versions prior to 9.20.0 have a path traversal vulnerability in the FileUtil…
Sharp
9.20.0+
HIGH 7.5
CVE-2026-33670
SiYuan is a personal knowledge management system. Prior to version 3.6.2, the /api/file/readDir interface was used to traverse and retrieve the file …
Siyuan
3.6.2+
HIGH 8.1
CVE-2026-33645
Fireshare facilitates self-hosted media and link sharing. In version 1.5.1, an authenticated path traversal vulnerability in Fireshare’s chunked uplo…
Fireshare
Mitigation only
MEDIUM 6.3
CVE-2026-0964
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could…
Hardened Images
0.11.4+
HIGH 8.8
CVE-2026-33529
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. Prior to version 3.3.2, an authenticated path traversal vulnerability in the conf…
Zoraxy
3.3.2+
MEDIUM 6.5
CVE-2026-33528
GoDoxy is a reverse proxy and container orchestrator for self-hosters. Prior to version 0.27.5, the file content API endpoint at `/api/v1/file/conten…
Godoxy
0.27.5+