Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.8
CVE-2026-32709
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, An unauthenticated path traversal vulnerability in the PX4 Autopilot MAVL…
Px4 Drone Autopilot
1.17.0+
MEDIUM 6.4
CVE-2026-32719
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, Th…
Anythingllm
after 1.11.1
HIGH 7.5
CVE-2026-2493
IceWarp collaboration Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive info…
Mitigation only
MEDIUM 5.5
CVE-2026-21000
Improper access control in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
Galaxy Store
4.6.03.8+
MEDIUM 5.5
CVE-2026-21001
Path traversal in Galaxy Store prior to version 4.6.03.8 allows local attacker to create file with Galaxy Store privilege.
Galaxy Store
4.6.03.8+
MEDIUM 6.5
CVE-2026-21005
Path traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.
Smart Switch
3.7.69.15+
HIGH 8.8
CVE-2026-4092
Path Traversal in Clasp impacting versions < 3.2.0 allows a remote attacker to perform remote code execution via a malicious Google Apps Script proje…
Clasp
3.2.0+
HIGH 7.6
CVE-2026-31886
Dagu is a workflow engine with a built-in Web user interface. Prior to 2.2.4, the dagRunId request field accepted by the inline DAG execution endpoin…
Dagu
2.2.4+
HIGH 8.2
CVE-2026-30853
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Prior to 9.5.0, a path traversal vulnerability i…
Calibre
9.5.0+
HIGH 8.1
CVE-2026-30914
SFTPGo is an open source, event-driven file transfer solution. In SFTPGo versions prior to 2.7.1, a path normalization discrepancy between the protoc…
Sftpgo
2.7.1+
MEDIUM 5.4
CVE-2026-23942
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal.
…
Erlang\/otp
5.1.4.14 / 5.2.11.6+
HIGH 7.5
CVE-2026-22199
Voltronic Power SNMP Web Pro version 1.1 contains a pre-authentication path traversal vulnerability in the upload.cgi endpoint that allows unauthenti…
Wpdiscuz
7.6.47+
MEDIUM 6.3
CVE-2025-66249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy.
This issue affects Apache Livy: from 0.…
Livy
0.9.0+
HIGH 7.5
CVE-2026-32274
Black is the uncompromising Python code formatter. Starting in version 24.3.0 and prior to version 26.3.1, Black writes a cache file, the name of whi…
Black
26.3.1+
CRITICAL 9.8
CVE-2026-32232
ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink A…
Zeptoclaw
after 0.7.5
HIGH 8.8
CVE-2026-32140
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC d…
Dataease
2.10.20+
HIGH 8.1
CVE-2026-32116
Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. From 0.21.0 to before 0.23.0, receiving a…
Magic Wormhole
0.23.0+
HIGH 7.4
CVE-2026-28791
Tina is a headless content management system. Prior to 2.1.7, a path traversal vulnerability exists in the TinaCMS development server's media upload …
Tinacms\/cli
2.1.7+
CRITICAL 9.6
CVE-2026-28792
Tina is a headless content management system. Prior to 2.1.8 , the TinaCMS CLI dev server combines a permissive CORS configuration (Access-Control-Al…
Tinacms\/cli
2.1.8+
HIGH 8.4
CVE-2026-28793
Tina is a headless content management system. Prior to 2.1.8, the TinaCMS CLI development server exposes media endpoints that are vulnerable to path …
Tinacms\/cli
2.1.8+
MEDIUM 6.3
CVE-2026-24125
Tina is a headless content management system. Prior to 2.1.2, TinaCMS allows users to create, update, and delete content documents using relative fil…
Tinacms\/graphql
2.1.2+
MEDIUM 6.5
CVE-2026-3954
A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the function workspace of the file XAgentServer/application…
Mitigation only
HIGH 7.5
CVE-2019-25480
ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulati…
No fix yet
CRITICAL 9.8
CVE-2019-25471
FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the…
File Thingie
after 2.5.7
MEDIUM 6.5
CVE-2026-30234
OpenProject is an open-source, web-based project management software. Prior to 17.2.0, an authenticated project member with BCF import permissions ca…
Openproject
17.2.0+
HIGH 7.1
CVE-2026-27897
Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py wi…
Vociferous
4.4.2+
HIGH 8.7
CVE-2026-3013
Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vuln…
Mitigation only
HIGH 8.8
CVE-2026-32060
OpenClaw versions prior to 2026.2.14 contain a path traversal vulnerability in apply_patch that allows attackers to write or delete files outside the…
Openclaw
2026.2.14+
MEDIUM 6.8
CVE-2026-21360
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pat…
Commerce
1.3.3 / 2.4.4+
HIGH 8.5
CVE-2026-31817
OliveTin gives access to predefined shell commands from a web interface. Prior to 3000.11.2, when the saveLogs feature is enabled, OliveTin persists …
Olivetin
3000.11.2+