Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-61372
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki.
This issue affects Apache Jena F…
Jena Fuseki
6.2.0+
HIGH 8.1
CVE-2026-62391
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-…
Kyuubi
1.12.0+
MEDIUM 6.5
CVE-2026-44615
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not…
Zeppelin
0.12.1+
HIGH 7.5
CVE-2026-66755
Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker…
Tika
3.3.2+
CRITICAL 9.8
CVE-2026-52680
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …
Kyuubi
1.12.0+
HIGH 7.5
CVE-2026-56452
Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH.
The impleme…
Mina Sshd
2.19.0+
HIGH 7.1
CVE-2026-56623
Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH.
A git s…
Mina Sshd
2.19.0+
MEDIUM 5.4
CVE-2026-26032
The PackagerResolver of Apache Ivy is able to download online
artifacts and to (re)package them in a format defined by a
packager.xml file. This repa…
Ivy
2.6.0+
MEDIUM 6.5
CVE-2026-49488
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings.
This issue affects Apache OpenM…
Openmeetings
9.1.0+
HIGH 8.1
CVE-2026-49297
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket …
Apache Airflow Providers Google
22.2.1+
HIGH 7.5
CVE-2026-47896
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
T…
Lucene.net
Mitigation only
HIGH 7.5
CVE-2026-47897
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library).
T…
Lucene.net
Mitigation only
CRITICAL 9.1
CVE-2026-50203
A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv…
Apache Airflow Providers Sftp
5.8.1+
MEDIUM 6.5
CVE-2026-49818
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec…
Apache Airflow Providers Samba
4.12.6+
HIGH 7.1
CVE-2026-48827
Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operati…
Mina Sshd
2.18.0+
MEDIUM 6.1
CVE-2026-31379
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-29220
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: befor…
Ofbiz
24.09.06+
MEDIUM 6.5
CVE-2026-43975
FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName
before constructing file p…
Wicket
10.9.0+
HIGH 7.3
CVE-2026-43870
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…
Thrift
0.23.0+
MEDIUM 6.3
CVE-2025-66249
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy.
This issue affects Apache Livy: from 0.…
Livy
0.9.0+
MEDIUM 5.3
CVE-2026-23907
This issue affects the
ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6.
The ExtractEmbeddedFil…
Pdfbox
after 3.0.7
HIGH 7.5
CVE-2025-29847
A vulnerability in Apache Linkis.
Problem Description
When using the JDBC engine and da
When using the JDBC engine and data source functionality, if…
Linkis
1.8.0+
HIGH 8.8
CVE-2025-66518
Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and…
Kyuubi
1.10.3+
HIGH 7.5
CVE-2025-49656
Users with administrator access can create databases files outside the files area of the Fuseki server.
This issue affects Apache Jena version up to…
Jena
5.5.0+
MEDIUM 5.4
CVE-2024-48019
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …
Doris
2.1.8 / 3.0.3+
CRITICAL 9.1
CVE-2024-36104EPSS 87%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…
Ofbiz
18.12.14+
CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …
Ofbiz
18.12.13+
MEDIUM 6.5
CVE-2024-31860
Improper Input Validation vulnerability in Apache Zeppelin.
By adding relative path indicators(E.g ..), attackers can see the contents for any files…
Zeppelin
0.11.0+
CRITICAL 9.9
CVE-2024-27317EPSS 57%
In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu…
Pulsar
2.10.6 / 2.11.4+
CRITICAL 9.1
CVE-2024-25065EPSS 48%
Possible path traversal in Apache OFBiz allowing authentication bypass.
Users are recommended to upgrade to version 18.12.12, that fixes the issue.
Ofbiz
18.12.12+