158 CVEs — updated 2026-09-18 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-85706 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 1 | CRITICAL | 10.0 | 96%ile | NVD | 2026-09-12 |
| CVE-2026-70200 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorize | CRITICAL | 10.0 | 47%ile | NVD | 2026-09-17 |
| CVE-2025-62878 | Local Path Provisioner vulnerable to Path Traversal via parameters.pathPattern | CRITICAL | 9.9 | 46%ile | Microsoft | 2026-02-10 |
| CVE-2026-76440 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc | CRITICAL | 9.8 | 39%ile | NVD | 2026-09-14 |
| CVE-2026-61560 | `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (` | CRITICAL | 9.8 | 52%ile | NVD | 2026-09-15 |
| CVE-2026-54617 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote | CRITICAL | 9.8 | 51%ile | NVD | 2026-09-17 |
| CVE-2026-45140 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a | CRITICAL | 9.8 | 61%ile | NVD | 2026-09-17 |
| CVE-2026-54053 | Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import impl | CRITICAL | 9.6 | 52%ile | NVD | 2026-09-17 |
| CVE-2026-89040 | Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request i | CRITICAL | 9.3 | 59%ile | NVD | 2026-09-15 |
| CVE-2026-70009 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attac | CRITICAL | 9.3 | 40%ile | NVD | 2026-09-17 |
| CVE-2026-78299 | In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extr | CRITICAL | 9.1 | 28%ile | NVD | 2026-09-14 |
| CVE-2026-57145 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, src/praisonai/praisonai/tools/multiedit.py passes the LLM-cont | CRITICAL | 9.1 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-50006 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL fro | CRITICAL | 9.1 | 54%ile | NVD | 2026-09-14 |
| CVE-2026-54670 | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/cont | CRITICAL | 9.1 | 45%ile | NVD | 2026-09-17 |
| CVE-2026-82428 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from t | HIGH | 8.8 | 51%ile | NVD | 2026-09-14 |
| CVE-2026-92137 | Jenkins Robot Framework Plugin 6.2.2 and earlier does not check that the archive directory configured for Robot Framewor | HIGH | 8.8 | 54%ile | NVD | 2026-09-16 |
| CVE-2026-85731 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked w | HIGH | 8.8 | 50%ile | NVD | 2026-09-16 |
| CVE-2026-89084 | HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, | HIGH | 8.8 | 46%ile | NVD | 2026-09-16 |
| CVE-2026-76409 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t | HIGH | 8.8 | 42%ile | NVD | 2026-09-16 |
| CVE-2026-15815 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug | HIGH | 8.8 | 57%ile | NVD | 2026-09-17 |
| CVE-2026-54612 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until | HIGH | 8.8 | 41%ile | NVD | 2026-09-17 |
| CVE-2025-69194 | Wget2: arbitrary file write via metalink path traversal in gnu wget2 | HIGH | 8.8 | 55%ile | Microsoft | 2026-01-13 |
| CVE-2026-90774 | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowi | HIGH | 8.7 | 32%ile | NVD | 2026-09-13 |
| CVE-2026-91200 | DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attack | HIGH | 8.7 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-91771 | Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function | HIGH | 8.7 | 53%ile | NVD | 2026-09-15 |
| CVE-2026-87791 | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Des | HIGH | 8.7 | 34%ile | NVD | 2026-09-15 |
| CVE-2026-91934 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite datab | HIGH | 8.7 | 51%ile | NVD | 2026-09-15 |
| CVE-2026-91940 | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_unt | HIGH | 8.7 | 36%ile | NVD | 2026-09-15 |
| CVE-2026-91989 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote | HIGH | 8.7 | 68%ile | NVD | 2026-09-15 |
| CVE-2026-81568 | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0- | HIGH | 8.7 | 26%ile | NVD | 2026-09-15 |
| CVE-2026-92355 | In affected versions of Octopus Server, a user with permission to modify non built-in external feeds could exploit a pat | HIGH | 8.7 | 51%ile | NVD | 2026-09-16 |
| CVE-2026-92748 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authent | HIGH | 8.7 | 50%ile | NVD | 2026-09-16 |
| CVE-2026-92791 | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated att | HIGH | 8.7 | 42%ile | NVD | 2026-09-16 |
| CVE-2026-92970 | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authentic | HIGH | 8.7 | 43%ile | NVD | 2026-09-17 |
| CVE-2026-86864 | pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/object request to the p | HIGH | 8.7 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-54343 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version | HIGH | 8.7 | 41%ile | NVD | 2026-09-17 |
| CVE-2026-93468 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit R | HIGH | 8.7 | 39%ile | NVD | 2026-09-18 |
| CVE-2017-20284 | Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthen | HIGH | 8.7 | — | NVD | 2026-09-18 |
| CVE-2026-82765 | Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is | HIGH | 8.6 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-82768 | Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be | HIGH | 8.6 | 29%ile | NVD | 2026-09-14 |
| CVE-2026-90932 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. C | HIGH | 8.6 | 39%ile | NVD | 2026-09-14 |
| CVE-2026-92816 | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to ar | HIGH | 8.5 | 5%ile | NVD | 2026-09-16 |
| CVE-2026-55062 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget | HIGH | 8.4 | 3%ile | NVD | 2026-09-17 |
| CVE-2026-54583 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-d | HIGH | 8.3 | 43%ile | NVD | 2026-09-17 |
| CVE-2026-54178 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha | HIGH | 8.1 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-16335 | IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to read, write, or | HIGH | 8.1 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-83357 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppo | HIGH | 8.1 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-54520 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior | HIGH | 8.1 | 34%ile | NVD | 2026-09-17 |
| CVE-2026-62278 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authen | HIGH | 8.1 | — | NVD | 2026-09-18 |
| CVE-2026-70460 | rsync 2.3.3 < 3.5.0 Path Traversal via --partial-dir/--backup-dir Symlink | HIGH | 8.1 | 38%ile | Microsoft | 2026-08-11 |
| CVE-2026-11816 | Path Traversal in keras-team/keras | HIGH | 8.1 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-82427 | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervi | HIGH | 7.8 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-43691 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia | HIGH | 7.8 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-64790 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Golden Gate 27, macOS Sequoia | HIGH | 7.8 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-84568 | A path traversal issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS S | HIGH | 7.8 | 6%ile | NVD | 2026-09-14 |
| CVE-2026-59974 | Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human language | HIGH | 7.8 | 40%ile | NVD | 2026-09-16 |
| CVE-2026-79655 | Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file wr | HIGH | 7.8 | 4%ile | Microsoft | 2026-08-11 |
| CVE-2026-73496 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th | HIGH | 7.7 | 26%ile | NVD | 2026-09-14 |
| CVE-2026-92812 | decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix | HIGH | 7.6 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-82896 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due | HIGH | 7.6 | — | NVD | 2026-09-18 |
| CVE-2026-57129 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts f | HIGH | 7.5 | 38%ile | NVD | 2026-09-14 |
| CVE-2026-57119 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing | HIGH | 7.5 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-15955 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file writ | HIGH | 7.5 | 34%ile | NVD | 2026-09-14 |
| CVE-2026-54629 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtu | HIGH | 7.5 | 60%ile | NVD | 2026-09-14 |
| CVE-2026-84598 | A path traversal issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS | HIGH | 7.5 | 32%ile | NVD | 2026-09-14 |
| CVE-2026-51134 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' paramete | HIGH | 7.5 | 79%ile | NVD | 2026-09-15 |
| CVE-2026-27557 | An unauthenticated remote attacker can exploit a path traversal vulnerability in the /index.php/view_uploaded_iodd_file | HIGH | 7.5 | 52%ile | NVD | 2026-09-16 |
| CVE-2026-81481 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res | HIGH | 7.5 | 44%ile | NVD | 2026-09-17 |
| CVE-2026-14323 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in | HIGH | 7.5 | 59%ile | NVD | 2026-09-18 |
| CVE-2025-14753 | IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send | HIGH | 7.5 | — | NVD | 2026-09-18 |
| CVE-2026-85396 | rubyzip before 3.4.0 Path Traversal in Zip::Entry#extract via Sibling-Directory Prefix | HIGH | 7.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-82251 | gitoxide before 0.52.1 Path Traversal via Submodule Name | HIGH | 7.5 | 33%ile | Microsoft | 2026-08-11 |
| CVE-2026-82253 | gitoxide before 0.82.0 Path Traversal via Submodule Name Validation Bypass | HIGH | 7.5 | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-78254 | Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write | HIGH | 7.4 | 44%ile | Microsoft | 2026-09-08 |
| CVE-2026-56839 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass | HIGH | 7.3 | 23%ile | NVD | 2026-09-14 |
| CVE-2026-47253 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar functi | HIGH | 7.3 | 31%ile | NVD | 2026-09-14 |
| CVE-2026-53554 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat | HIGH | 7.3 | 30%ile | NVD | 2026-09-17 |
| CVE-2026-91751 | Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing | HIGH | 7.2 | 28%ile | NVD | 2026-09-15 |
| CVE-2026-92604 | Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows d | HIGH | 7.2 | 43%ile | NVD | 2026-09-16 |
| CVE-2026-87976 | Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using g | HIGH | 7.2 | 32%ile | NVD | 2026-09-16 |
| CVE-2026-92919 | admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to | HIGH | 7.2 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-84086 | IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper | HIGH | 7.2 | — | NVD | 2026-09-18 |
| CVE-2026-82035 | PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_o | HIGH | 7.1 | 25%ile | NVD | 2026-09-14 |
| CVE-2026-54077 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/quer | HIGH | 7.1 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-93014 | RosarioSIS versions before 12.9 fail to validate the filename request parameter in Users and Students modules, allowing | HIGH | 7.1 | 33%ile | NVD | 2026-09-17 |
| CVE-2026-63445 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoint | HIGH | 7.1 | — | NVD | 2026-09-18 |
| CVE-2026-53784 | rsync < 3.5.0 Path Traversal via Symlink Module Root | HIGH | 7.1 | 15%ile | Microsoft | 2026-08-11 |
| CVE-2026-53785 | rsync < 3.5.0 Path Traversal Write Escape via --relative Mode | HIGH | 7.1 | 9%ile | Microsoft | 2026-08-11 |
| CVE-2026-82455 | RubyGems before 4.0.13 Path Traversal via Symlink Resolution | HIGH | 7.1 | — | Microsoft | 2026-08-11 |
| CVE-2026-81564 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP P | HIGH | 7.0 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-90494 | A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/pl | MEDIUM | 6.9 | 45%ile | NVD | 2026-09-13 |
| CVE-2026-81565 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0. | MEDIUM | 6.9 | 24%ile | NVD | 2026-09-14 |
| CVE-2026-54150 | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-vide | MEDIUM | 6.9 | 31%ile | NVD | 2026-09-14 |
| CVE-2026-89021 | MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractio | MEDIUM | 6.9 | 16%ile | NVD | 2026-09-14 |
| CVE-2026-57442 | MCPVault is a lightweight Model Context Protocol server for safe access to files in an Obsidian vault. Prior to 0.11.5, | MEDIUM | 6.9 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-89038 | Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co | MEDIUM | 6.9 | 4%ile | NVD | 2026-09-17 |
| CVE-2026-93751 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlon | MEDIUM | 6.9 | — | NVD | 2026-09-18 |
| CVE-2026-76555 | The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a user-supplied file path before reading it a | MEDIUM | 6.8 | 39%ile | NVD | 2026-09-16 |
| CVE-2026-82426 | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a serv | MEDIUM | 6.5 | 42%ile | NVD | 2026-09-14 |
| CVE-2026-43791 | A validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Se | MEDIUM | 6.5 | 39%ile | NVD | 2026-09-14 |
| CVE-2026-81453 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res | MEDIUM | 6.5 | 38%ile | NVD | 2026-09-17 |
| CVE-2026-40535 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synolo | MEDIUM | 6.5 | 37%ile | NVD | 2026-09-18 |
| CVE-2026-59149 | @Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only | MEDIUM | 6.5 | 41%ile | GitHub | 2026-09-11 |
| CVE-2026-21822 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handl | MEDIUM | 6.3 | 12%ile | NVD | 2026-09-18 |
| CVE-2026-55846 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP ser | MEDIUM | 6.2 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-54561 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_i | MEDIUM | 6.2 | 23%ile | NVD | 2026-09-15 |
| CVE-2026-55832 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2 | MEDIUM | 6.1 | 15%ile | NVD | 2026-09-14 |
| CVE-2026-59944 | Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or | MEDIUM | 6.1 | 39%ile | NVD | 2026-09-16 |
| CVE-2026-55828 | qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses stric | MEDIUM | 6.0 | 31%ile | NVD | 2026-09-15 |
| CVE-2026-54585 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did | MEDIUM | 6.0 | 43%ile | NVD | 2026-09-17 |
| CVE-2026-69201 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode | MEDIUM | 5.9 | 49%ile | NVD | 2026-09-15 |
| CVE-2026-58015 | Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive | MEDIUM | 5.9 | 50%ile | Microsoft | 2026-06-09 |
| CVE-2026-90691 | A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The imp | MEDIUM | 5.5 | 37%ile | NVD | 2026-09-14 |
| CVE-2026-64756 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden | MEDIUM | 5.5 | 8%ile | NVD | 2026-09-14 |
| CVE-2026-65382 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m | MEDIUM | 5.5 | 7%ile | NVD | 2026-09-14 |
| CVE-2026-65411 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 an | MEDIUM | 5.5 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-84534 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 an | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-84541 | An input validation issue was addressed with improved input validation. This issue is fixed in macOS Golden Gate 27, mac | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-84624 | A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 | MEDIUM | 5.5 | 4%ile | NVD | 2026-09-14 |
| CVE-2026-86886 | A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iO | MEDIUM | 5.5 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-86902 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m | MEDIUM | 5.5 | 3%ile | NVD | 2026-09-14 |
| CVE-2026-86910 | A permissions issue was addressed with improved path validation. This issue is fixed in macOS Golden Gate 27, macOS Sequ | MEDIUM | 5.5 | 5%ile | NVD | 2026-09-14 |
| CVE-2026-64400 | ksmbd: prevent path traversal bypass by restricting caseless retry | MEDIUM | 5.5 | 29%ile | Microsoft | 2026-07-14 |
| CVE-2026-54613 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5 | MEDIUM | 5.4 | 15%ile | NVD | 2026-09-17 |
| CVE-2026-47256 | OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating | MEDIUM | 5.3 | 36%ile | NVD | 2026-09-14 |
| CVE-2026-50024 | GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_ta | MEDIUM | 5.3 | 38%ile | NVD | 2026-09-15 |
| CVE-2026-76433 | A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticate | MEDIUM | 5.3 | 59%ile | NVD | 2026-09-16 |
| CVE-2026-81829 | A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by | MEDIUM | 5.3 | 33%ile | NVD | 2026-09-17 |
| CVE-2026-93013 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadat | MEDIUM | 5.3 | 29%ile | NVD | 2026-09-17 |
| CVE-2026-76431 | A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC cou | MEDIUM | 4.9 | 65%ile | NVD | 2026-09-16 |
| CVE-2026-76432 | A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remot | MEDIUM | 4.9 | 58%ile | NVD | 2026-09-16 |
| CVE-2026-76434 | A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE | MEDIUM | 4.9 | 19%ile | NVD | 2026-09-16 |
| CVE-2026-16777 | The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to | MEDIUM | 4.9 | 50%ile | NVD | 2026-09-18 |
| CVE-2026-47215 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4. | MEDIUM | 4.8 | 4%ile | NVD | 2026-09-15 |
| CVE-2026-48785 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix | MEDIUM | 4.8 | 2%ile | NVD | 2026-09-15 |
| CVE-2026-55374 | canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUr | MEDIUM | 4.8 | 14%ile | NVD | 2026-09-15 |
| CVE-2025-11563 | wcurl path traversal with percent-encoded slashes | MEDIUM | 4.6 | 30%ile | Microsoft | 2026-02-10 |
| CVE-2026-79705 | A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar arch | MEDIUM | 4.5 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-63225 | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the spl | MEDIUM | 4.4 | 7%ile | NVD | 2026-09-16 |
| CVE-2026-18515 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Naviga | MEDIUM | 4.3 | 20%ile | NVD | 2026-09-14 |
| CVE-2026-40536 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology | MEDIUM | 4.3 | 31%ile | NVD | 2026-09-18 |
| CVE-2026-85272 | Open edX Platform enables the authoring and delivery of online learning at any scale. From Aspen.1 until Ulmo and Verawo | MEDIUM | 4.3 | — | NVD | 2026-09-18 |
| CVE-2026-53584 | libgit2: Submodule path traversal | MEDIUM | 4.3 | 26%ile | Microsoft | 2026-08-11 |
| CVE-2026-92131 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to | MEDIUM | 4.2 | 13%ile | NVD | 2026-09-16 |
| CVE-2026-86071 | Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/git | LOW | 3.7 | 23%ile | NVD | 2026-09-16 |
| CVE-2025-70820 | Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder. | LOW | 3.5 | 8%ile | NVD | 2026-09-13 |
| CVE-2026-45723 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat | LOW | 2.7 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-92945 | vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix | LOW | 2.3 | 12%ile | NVD | 2026-09-17 |
| CVE-2025-59825 | astral-tokio-tar has a path traversal in tar extraction | UNKNOWN | — | 12%ile | Microsoft | 2025-09-09 |
| CVE-2026-64653 | GitHub CLI: Unescaped variable components in request URLs could allow path traversal | UNKNOWN | — | 42%ile | Microsoft | 2026-08-11 |
| CVE-2026-66484 | Path Traversal in GNU cpio | UNKNOWN | — | 5%ile | Microsoft | 2026-08-11 |
| CVE-2026-44307 | Mako: Path traversal via backslash URI on Windows in TemplateLookup | UNKNOWN | — | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-13346 | pip absolute path traversal during download from malicious package indexes | UNKNOWN | — | 22%ile | Microsoft | 2026-07-14 |
| CVE-2026-7774 | tarfile.data_filter path traversal bypass allows writing outside the extraction directory | UNKNOWN | — | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-44705 | tmp: Path Traversal via unsanitized prefix/postfix enables directory escape | UNKNOWN | — | 37%ile | Microsoft | 2026-06-09 |
| CVE-2026-1703 | Limited path traversal when installing wheel archives | UNKNOWN | — | 35%ile | Microsoft | 2026-02-10 |
| CVE-2026-21620 | TFTP Path Traversal | UNKNOWN | — | 39%ile | Microsoft | 2026-02-10 |
| FG-IR-26-151 | Path traversal in CLI command allows deletion of root file system | UNKNOWN | — | — | Fortinet | 2026-07-14 |