Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-27704
The Dart and Flutter SDKs provide software development kits for the Dart programming language. In versions of the Dart SDK prior to 3.11.0 and the Fl…
Dart Software Development Kit
3.11.0 / 3.41.0+
CRITICAL 9.8
CVE-2026-27699
The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` m…
Basic Ftp
5.2.0+
CRITICAL 9.1
CVE-2026-0704
In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked va…
Octopus Server
2025.3.14715+
HIGH 8.1
CVE-2026-3179
The FTP Backup on the ADM does not properly sanitize filenames received from the FTP server when parsing directory listings. A malicious server or MI…
Data Master
5.1.2.reo1+
CRITICAL 9.8
CVE-2026-25785
Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacke…
Lanscope Endpoint Manager
9.4.8.0+
CRITICAL 9.8
CVE-2026-27641
Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remo…
Flask Reuploaded
1.5.0+
CRITICAL 9.8
CVE-2026-27606
Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present i…
Rollup
2.80.0 / 3.30.0+
MEDIUM 6.5
CVE-2026-24849
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument…
Openemr
7.0.4+
MEDIUM 6.5
CVE-2026-27598
Dagu is a workflow engine with a built-in Web user interface. In versions up to and including 1.16.7, the `CreateNewDAG` API endpoint (`POST /api/v1/…
Dagu
after 1.16.7
HIGH 7.5
CVE-2026-27117
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.11, a path traversal vulne…
Bit7z
4.0.11+
HIGH 7.5
CVE-2026-25891
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the sta…
Fiber
3.1.0+
MEDIUM 6.6
CVE-2026-25603
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Linksys MR9600, Linksys MX4200 allows that contents o…
Mr9600 Firmware
No fix yet
HIGH 8.8
CVE-2026-27483EPSS 11%
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability i…
Mindsdb
25.9.1.1+
HIGH 7.2
CVE-2025-15589
A vulnerability was determined in MuYuCMS 2.7. Affected is the function delete_dir_file of the file application/admin/controller/Template.php of the …
Muyucms
No fix yet
HIGH 8.8
CVE-2026-3067
A vulnerability has been found in HummerRisk up to 1.5.0. This issue affects the function extractTarGZ/extractZip of the file hummer-common/hummer-co…
Hummerrisk
after 1.5.0
HIGH 7.5
CVE-2026-25965
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, ImageMagick’…
Imagemagick
6.9.13-40 / 7.1.2-15+
HIGH 7.6
CVE-2026-3051EPSS 6%
A vulnerability has been found in DataLinkDC dinky up to 1.2.5. The affected element is the function getProjectDir of the file dinky-admin/src/main/j…
Dinky
after 1.2.5
MEDIUM 6.5
CVE-2026-23521
Versions of the Traccar open-source GPS tracking system up to and including 6.11.1 contain an issue in which authenticated users who can create or ed…
Traccar
after 6.11.1
CRITICAL 9.1
CVE-2026-2953
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o…
Ujcms
No fix yet
MEDIUM 5.4
CVE-2026-2864
A vulnerability has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. This affects the func…
Mitigation only
MEDIUM 5.4
CVE-2026-2863
A flaw has been found in feng_ha_ha/megagao ssm-erp and production_ssm up to 4288d53bd35757b27f2d070057aefb2c07bdd097. The impacted element is the fu…
Mitigation only
HIGH 7.5
CVE-2026-27202
GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file …
Getsimple Cms
No fix yet
HIGH 7.3
CVE-2026-2033
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execut…
Patch available
HIGH 7.1
CVE-2026-27115
ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigge…
Adb Explorer
0.9.26021+
HIGH 8.2
CVE-2026-2818
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended ext…
Mitigation only
MEDIUM 6.5
CVE-2026-24953
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list all…
Mitigation only
HIGH 8.6
CVE-2025-69376
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allow…
Mitigation only
HIGH 7.7
CVE-2025-69377
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish User Extra Fields wp-user-extra-fields allow…
Mitigation only
HIGH 8.6
CVE-2025-69379
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhe…
Mitigation only
HIGH 7.5
CVE-2025-69380
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhe…
Mitigation only