Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2026-52680
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …
Kyuubi
1.12.0+
HIGH 7.5
CVE-2026-6540
Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re…
Calico
3.21.7 / 3.22.4+
CRITICAL 9.8
CVE-2026-15435
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the sy…
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
HIGH 7.5
CVE-2026-14519
IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a …
App Connect Enterprise
12.0.12.28 / 13.0.8.0+
CRITICAL 9.8
CVE-2026-59310 KEV
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…
Vcenter Server
No fix yet
MEDIUM 5.3
CVE-2026-16531
An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows…
No fix yet
MEDIUM 6.5
CVE-2026-67247
A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlled disk serial input is not su…
Data Master
5.1.4.rjv2+
HIGH 8.1
CVE-2026-67245
A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is no…
Data Master
5.1.4.rjv2+
MEDIUM 6.5
CVE-2026-67246
A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-controlled wallpaper path input is …
Data Master
5.1.4.rjv2+
HIGH 7.5
CVE-2026-5491
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
MEDIUM 6.5
CVE-2026-5492
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
HIGH 7.5
CVE-2026-5487
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
MEDIUM 5.3
CVE-2026-5489
DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…
No fix yet
CRITICAL 10.0
CVE-2026-67429
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller…
Mitigation only
MEDIUM 6.5
CVE-2026-13723
A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by expl…
No fix yet
MEDIUM 5.9
CVE-2026-50558
Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in p…
No fix yet
HIGH 7.5
CVE-2026-65886
Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view …
Gridbox
2.20.2+
HIGH 7.5
CVE-2026-65889
Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…
Gridbox
2.20.2+
MEDIUM 6.9
CVE-2026-44943
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create…
No fix yet
HIGH 8.6
CVE-2026-11974
The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two A…
No fix yet
MEDIUM 6.5
CVE-2026-66063
goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler s…
No fix yet
MEDIUM 6.9
CVE-2026-54659
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver…
No fix yet
HIGH 8.6
CVE-2026-54650
openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.P…
No fix yet
HIGH 7.5
CVE-2026-55389
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…
Datamodel Code Generator
0.62.0+
HIGH 7.5
CVE-2026-55390
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_gen…
No fix yet
HIGH 7.5
CVE-2026-15280
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i…
Websphere Application Server
26.0.0.9+
CRITICAL 9.3
CVE-2026-14973
IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.
Aspera
after 1.0.19
HIGH 7.8
CVE-2026-48374
Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary fi…
Bridge
15.1.7 / 16.0.6+
HIGH 7.5
CVE-2026-67185
TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequenc…
No fix yet
HIGH 7.1
CVE-2026-54545
wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once …
No fix yet