Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.9
CVE-2026-24848EPSS 6%
OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() …
Openemr
7.0.4+
MEDIUM 6.5
CVE-2026-2606
IBM webMethods API Gateway (on-prem) 10.11 through 10.11_Fix3210.15 to 10.15_Fix2711.1 to 11.1_Fix7 IBM webMethods API Management (on-prem) fails to …
Webmethods Api Gateway
Mitigation only
HIGH 7.8
CVE-2026-28518
OpenViking versions 0.2.1 and prior, fixed in commit 46b3e76, contain a path traversal vulnerability in the .ovpack import handling that allows attac…
Openviking
0.2.1+
HIGH 8.8
CVE-2026-2448
The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.33.5 via the locate…
Mitigation only
HIGH 8.4
CVE-2025-48636
In openFile of BugreportContentProvider.java, there is a possible way to read and write unauthorized files due to a path traversal error. This could …
Android
Mitigation only
HIGH 7.8
CVE-2025-48567
In multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrect unicode…
Android
Mitigation only
HIGH 8.0
CVE-2026-0655
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TP-Link Deco BE25 v1.0 (web modules) allows authentic…
Deco Be25 Firmware
after 1.1.1
HIGH 8.1
CVE-2026-3405
A vulnerability has been found in thinkgem JeeSite up to 5.15.1. The affected element is an unknown function of the component Connection Handler. The…
Jeesite
after 5.15.1
HIGH 7.5
CVE-2026-28414
Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vul…
Gradio
6.7.0+
HIGH 8.2
CVE-2026-28406
kaniko is a tool to build container images from a Dockerfile, inside a container or Kubernetes cluster. Starting in version 1.25.4 and prior to versi…
Kaniko
1.25.10+
MEDIUM 6.5
CVE-2026-27734
Beszel is a server monitoring platform. Prior to version 0.18.2, the hub's authenticated API endpoints GET /api/beszel/containers/logs and GET /api/b…
Beszel
0.18.2+
MEDIUM 6.5
CVE-2026-24488
OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, an ar…
Openemr
after 8.0.0
HIGH 8.8
CVE-2026-2749
Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on…
Open Tickets
24.04.7 / 24.10.8+
HIGH 7.8
CVE-2026-3223
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
Web Designer
No fix yet
CRITICAL 9.8
CVE-2026-21659
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Q…
Frick Controls Quantum Hd Firmware
after 10.22
CRITICAL 9.8
CVE-2026-2251
Improper limitation of a pathname to a restricted directory (Path Traversal) vulnerability in Xerox FreeFlow Core allows unauthorized path traversal …
Freeflow Core
8.1.0+
CRITICAL 9.8
CVE-2026-3289
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the…
Publiccms
Mitigation only
CRITICAL 9.1
CVE-2026-22877
An arbitrary file-read vulnerability exists in XWEB Pro version 1.12.1
and prior, enabling unauthenticated attackers to read arbitrary files on
the…
Xweb 300d Pro Firmware
after 1.12.1
MEDIUM 5.9
CVE-2026-28208EPSS 12%
Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows …
Junrar
7.5.8+
HIGH 7.5
CVE-2026-23939
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Store.Local' module)…
Hexpm
2026-02-26+
CRITICAL 9.8
CVE-2025-50857
ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code v…
Mitigation only
HIGH 8.8
CVE-2026-1311
The Worry Proof Backup plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 0.2.4 via the backup upload functio…
Mitigation only
HIGH 8.8
CVE-2026-27969
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the bac…
Vitess
22.0.4 / 23.0.3+
HIGH 7.5
CVE-2026-1557
The WP Responsive Images plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0 via the 'src' parameter. This…
Mitigation only
MEDIUM 5.3
CVE-2026-27884
NetExec is a network execution tool. Prior to version 1.5.1, the module spider_plus improperly creates the output file and folder path when saving fi…
Patch available
MEDIUM 6.5
CVE-2026-27735
Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to…
Model Context Protocol Servers
2026.1.14+
HIGH 7.4
CVE-2026-27800
Zed, a code editor, has a Zip Slip (Path Traversal) vulnerability exists in its extension archive extraction functionality prior to version 0.224.4. …
Zed
0.224.4+
HIGH 7.2
CVE-2026-27819
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the restoreConfig function in vikunja/pkg/modules/dump/restor…
Vikunja
2.0.0+
HIGH 8.8
CVE-2026-26984
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …
Loris
26.0.5 / 27.0.2+
MEDIUM 6.5
CVE-2026-26985
LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …
Loris
26.0.5 / 27.0.2+