Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-32771
The CTFer.io Monitoring component is in charge of the collection, process and storage of various signals (i.e. logs, metrics and distributed traces).…
Monitoring
0.2.2+
MEDIUM 6.5
CVE-2026-32758
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.6…
Filebrowser
2.62.0+
MEDIUM 5.9
CVE-2026-22737
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of co…
Spring Framework
5.3.47 / 6.1.26+
MEDIUM 6.8
CVE-2026-32750
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importStdMd passes the localPath parameter directly t…
Siyuan
3.6.1+
HIGH 8.2
CVE-2026-32036
OpenClaw gateway plugin versions prior to 2026.2.26 contain a path traversal vulnerability that allows remote attackers to bypass route authenticatio…
Openclaw
2026.2.6+
HIGH 7.5
CVE-2026-32030
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the stageSandboxMedia function that accepts arbitrary absolute paths w…
Openclaw
2026.2.19+
MEDIUM 6.5
CVE-2026-32033
OpenClaw versions prior to 2026.2.24 contain a path traversal vulnerability where @-prefixed absolute paths bypass workspace-only file-system boundar…
Openclaw
2026.2.24+
HIGH 8.6
CVE-2026-32026
OpenClaw versions prior to 2026.2.24 contain an improper path validation vulnerability in sandbox media handling that allows absolute paths under the…
Openclaw
2026.2.24+
MEDIUM 5.5
CVE-2026-32020
OpenClaw versions prior to 2026.2.22 contain a path traversal vulnerability in the static file handler that follows symbolic links, allowing out-of-r…
Openclaw
2026.2.22+
HIGH 8.1
CVE-2026-32007
OpenClaw versions prior to 2026.2.23 contain a path traversal vulnerability in the experimental apply_patch tool that allows attackers with sandbox a…
Openclaw
2026.2.23+
CRITICAL 9.1
CVE-2026-32749
SiYuan is a personal knowledge management system. In versions 3.6.0 and below, POST /api/import/importSY and POST /api/import/importZipMd write uploa…
Siyuan
3.6.1+
MEDIUM 6.5
CVE-2026-25928
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export featu…
Openemr
8.0.0.2+
MEDIUM 6.5
CVE-2025-67115
A path traversal vulnerability in /ftl/web/setup.cgi in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows …
Mitigation only
HIGH 7.5
CVE-2026-30403
There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can …
Wgcloud
after 3.6.3
HIGH 7.5
CVE-2026-3029
A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5.
Patch available
CRITICAL 10.0
CVE-2026-22557EPSS 28%
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in the UniFi Network Application to access files on t…
Mitigation only
HIGH 7.5
CVE-2026-32805
Romeo gives the capability to reach high code coverage of Go ≥1.20 apps by helping to measure code coverage for functional and integration tests with…
Romeo
0.2.2+
CRITICAL 9.9
CVE-2026-32731
ApostropheCMS is an open-source content management framework. Prior to version 3.5.3 of `@apostrophecms/import-export`,
The `extract()` function in `…
Import Export
3.5.3+
CRITICAL 9.1
CVE-2025-15031
A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar archive entries. Specifically,…
Mlflow
after 3.10.1
HIGH 8.8
CVE-2026-33001
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing…
Jenkins
2.541.3 / 2.555+
MEDIUM 5.5
CVE-2026-27522
OpenClaw versions prior to 2026.2.24 contain a local media root bypass vulnerability in sendAttachment and setGroupIcon message actions when sandboxR…
Openclaw
2026.2.24+
HIGH 7.5
CVE-2026-27523
OpenClaw versions prior to 2026.2.24 contain a sandbox bind validation vulnerability allowing attackers to bypass allowed-root and blocked-path check…
Openclaw
2026.2.24+
CRITICAL 9.1
CVE-2026-22171
OpenClaw versions prior to 2026.2.19 contain a path traversal vulnerability in the Feishu media download flow where untrusted media keys are interpol…
Openclaw
2026.2.19+
HIGH 7.5
CVE-2026-32981
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and san…
Ray
2.8.1+
HIGH 7.2
CVE-2026-25770
Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 3.9.0 and prior to version 4.14.3, …
Wazuh
4.14.3+
MEDIUM 5.5
CVE-2026-21991
A DTrace component, dtprobed, allows arbitrary file creation through crafted USDT provider names.
Linux
Mitigation only
HIGH 8.7
CVE-2026-29522
ZwickRoell Test Data Management versions prior to 3.0.8 contain a local file inclusion (LFI) vulnerability in the /server/node_upgrade_srv.js endpoin…
Mitigation only
HIGH 7.5
CVE-2025-66687
Doom Launcher 3.8.1.0 is vulnerable to Directory Traversal due to missing file path validation during the extraction of game files
Mitigation only
HIGH 7.3
CVE-2026-3839
Unraid Authentication Request Path Traversal Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication…
Unraid
Mitigation only
HIGH 8.8
CVE-2026-3838
Unraid Update Request Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff…
Unraid
Mitigation only