| React Router Session Path Traversal (CVE-2025-61686)
new CVE-2025-61686
web
Unverified | CVE-2025-61686 | web | CRITICAL 9.1 | Unverified | 2026-09-03 |
| Node.js Permission Model Symlink Escape (CVE-2025-55130)
new CVE-2025-55130
binary
Unverified | CVE-2025-55130 | binary | CRITICAL 9.1 | Unverified | 2026-09-03 |
| Next.js Windows Cache Path Traversal RCE (CVE-2026-75604)
new CVE-2026-75604
web
Unverified | CVE-2026-75604 | web | CRITICAL 9 | Unverified | 2026-09-03 |
| UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)
new
KEV
EPSS 87% CVE-2026-34910, CVE-2026-34909, CVE-2026-34908
network
Patched | CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 | network | CRITICAL 10 | Patched | 2026-08-16 |
| Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)
new CVE-2026-47301
network
Unverified | CVE-2026-47301 | network | CRITICAL 9.8 | Unverified | 2026-08-15 |
| Docker — CopyEscape: Container-to-Host Escape via docker cp Race Condition (CVE-2026-17106)
new CVE-2026-17106
binary
Unverified | CVE-2026-17106 | binary | CRITICAL 9.8 | Unverified | 2026-08-15 |
| Oracle E-Business Suite Pre-Authentication RCE Chain (CVE-2025-61882)
new
KEV
RW
EPSS 100% CVE-2025-61882 (Oracle Security Alert, out-of-band, October 2025)
web
Patched | CVE-2025-61882 | web | CRITICAL 9.8 | Patched | 2026-08-09 |
| Microweber CMS Unauthenticated Path Traversal → Arbitrary File Read (CVE-2026-65694)
new CVE-2026-65694 (VulnCheck advisory)
web
Patched | CVE-2026-65694 | web | HIGH 7.5 | Patched | 2026-07-31 |
| Adobe ColdFusion RDS Path Traversal → Arbitrary File Read/Write → RCE (CVE-2026-48282)
new
KEV
EPSS 42% CVE-2026-48282 (Adobe APSB26-68)
web
Patched | CVE-2026-48282 | web | CRITICAL 10 | Patched | 2026-07-19 |
| Crawl4AI Docker API Server Arbitrary File Write via `output_path` (CVE-2026-56260)
new CVE-2026-56260 (GHSA-365w-hqf6-vxfg)
web
Patched | CVE-2026-56260 | web | CRITICAL 9.1 | Patched | 2026-07-12 |
| ZKTeco BioTime v8.5.5 Unauthenticated Path Traversal / Arbitrary File Read via iclock API (CVE-2023-38950)
new
KEV
EPSS 85% CVE-2023-38950
web
Patched | CVE-2023-38950 | web | HIGH 7.5 | Patched | 2026-07-11 |
| Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)
new
KEV
EPSS 24% CVE-2025-4632
web
Patched | CVE-2025-4632 | web | CRITICAL 9.8 | Patched | 2026-07-06 |
| Python tarfile `filter="data"` Bypass via PATH_MAX/realpath Confusion (CVE-2025-4517)
new CVE-2025-4517
misc
Patched | CVE-2025-4517 | misc | CRITICAL 9.4 | Patched | 2026-07-06 |
| Pterodactyl Panel Unauthenticated Path Traversal via locale.json Leaking Database Credentials (CVE-2025-49132)
new
EPSS 53% CVE-2025-49132
web
Patched | CVE-2025-49132 | web | CRITICAL 10 | Patched | 2026-07-06 |
| Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)
new CVE-2025-52913
network
Unverified | CVE-2025-52913 | network | CRITICAL 9.8 | Unverified | 2026-07-06 |
| FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)
new
KEV
EPSS 92% CVE-2025-64446
network
Unverified | CVE-2025-64446 | network | CRITICAL 9.8 | Unverified | 2026-07-06 |
| Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)
new
KEV
EPSS 71% CVE-2025-20333
network
Unverified | CVE-2025-20333 | network | CRITICAL 9.9 | Unverified | 2026-07-06 |
| ZimaOS Arbitrary File Write via Unvalidated File API Path — CVE-2026-28286
new CVE-2026-28286
web
Unverified | CVE-2026-28286 | web | CRITICAL | Unverified | 2026-07-05 |
| WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)
new
EPSS 33% CVE-2026-1357
web
Unverified | CVE-2026-1357 | web | CRITICAL | Unverified | 2026-07-05 |
| Veno File Manager Path Traversal to Arbitrary File Read (CVE-2026-37066)
new CVE-2026-37066
web
Unverified | CVE-2026-37066 | web | HIGH | Unverified | 2026-07-05 |
| UnPoller Path Traversal / Arbitrary File Read via file:// Password Prefix (CVE-2026-36851)
new CVE-2026-36851
misc
Unverified | CVE-2026-36851 | misc | HIGH 7.5 | Unverified | 2026-07-05 |
| TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
new CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653)
network
Unverified | CVE-2026-0651 | network | CRITICAL | Unverified | 2026-07-05 |
| Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)
new CVE-2026-25964 (GHSA-6485-jr28-52xx)
web
Patched | CVE-2026-25964 | web | MEDIUM 4.9 | Patched | 2026-07-05 |
| Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)
new
EPSS 12% CVE-2026-1056
web
Unverified | CVE-2026-1056 | web | CRITICAL | Unverified | 2026-07-05 |
| Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
new CVE-2026-11912
web
Patched | CVE-2026-11912 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
new CVE-2026-4350
web
Unverified | CVE-2026-4350 | web | HIGH 8.1 | Unverified | 2026-07-05 |
| OpenPLC_v3 glue_generator Path Traversal — CVE-2026-31156
new CVE-2026-31156
hardware
Unverified | CVE-2026-31156 | hardware | HIGH | Unverified | 2026-07-05 |
| OpenEMR EtherFax Module Authenticated Arbitrary File Read (CVE-2026-24849)
new CVE-2026-24849
web
Patched | CVE-2026-24849 | web | CRITICAL 6.5 | Patched | 2026-07-05 |
| Node.js `tar` Package Symlink Path Traversal — CVE-2026-29786
new CVE-2026-29786
misc
Patched | CVE-2026-29786 | misc | HIGH | Patched | 2026-07-05 |
| node-tar Hardlink/Symlink Path Traversal Arbitrary File Overwrite (CVE-2026-23745)
new CVE-2026-23745 / GHSA-8qq5-rm4j-mr97
misc
Patched | CVE-2026-23745 / GHSA-8qq5-rm4j-mr97 | misc | HIGH | Patched | 2026-07-05 |
| Nezha Dashboard Path Traversal → JWT Secret Leak → Token Forgery — CVE-2026-53519
new CVE-2026-53519 (GHSA-5c25-7vpj-9mqh)
web
Patched | CVE-2026-53519 | web | INFO | Patched | 2026-07-05 |
| MindsDB — Handler Path Traversal to Remote Code Execution (CVE-2026-27483)
new
EPSS 11% CVE-2026-27483
web
Patched | CVE-2026-27483 | web | CRITICAL | Patched | 2026-07-05 |
| mcp-atlassian Path Traversal via confluence_upload_attachment (CVE-2026-27825)
new
EPSS 13% CVE-2026-27825 (read-side twin of GHSA-xjgw-4wvw-rgm4)
web
Patched | CVE-2026-27825 | web | CRITICAL 9.3 | Patched | 2026-07-05 |
| LiquidJS Template Engine Path Traversal — CVE-2026-30952
new CVE-2026-30952 (GHSA-wmfp-5q7x-987x)
misc
Patched | CVE-2026-30952 | misc | HIGH 8.7 | Patched | 2026-07-05 |
| Langflow Knowledge Base Path Traversal / Arbitrary Directory Deletion (CVE-2026-42048)
new CVE-2026-42048 (GHSA-9whx-c884-c68q)
web
Patched | CVE-2026-42048 | web | HIGH | Patched | 2026-07-05 |
| iOS App Intents Path Traversal — CVE-2026-28995
new CVE-2026-28995
misc
Patched | CVE-2026-28995 | misc | HIGH | Patched | 2026-07-05 |
| InvoicePlane Unauthenticated Path Traversal in Guest Controller (CVE-2026-23491)
new CVE-2026-23491
web
Patched | CVE-2026-23491 | web | CRITICAL | Patched | 2026-07-05 |
| Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
new CVE-2026-48866
web
Patched | CVE-2026-48866 | web | CRITICAL 9.6 | Patched | 2026-07-05 |
| Gogs Wiki Arbitrary File Deletion via Path Traversal (CVE-2026-24135)
new CVE-2026-24135 (GHSA-jp7c-wj6q-3qf2)
web
Patched | CVE-2026-24135 | web | HIGH 7.5 | Patched | 2026-07-05 |
| Gogs Organization-Name Path Traversal to RCE via Git Hooks — CVE-2026-52813
new CVE-2026-52813
web
Patched | CVE-2026-52813 | web | INFO | Patched | 2026-07-05 |
| FUXA SCADA/HMI — Unauthenticated Path Traversal to Remote Code Execution (CVE-2026-25895)
new
EPSS 11% CVE-2026-25895
web
Patched | CVE-2026-25895 | web | CRITICAL 9.8 | Patched | 2026-07-05 |
| EspoCRM Authenticated RCE via Formula ACL Bypass + Attachment Path Traversal — CVE-2026-33656
new CVE-2026-33656
web
Patched | CVE-2026-33656 | web | CRITICAL | Patched | 2026-07-05 |
| Centreon Multi-Vector RCE — Path Traversal, Command Injection & Blind SQLi (CVE-2026-2749)
new CVE-2026-2749 (bundled with related CVE-2026-2750, CVE-2026-2751)
web
Patched | CVE-2026-2749 | web | CRITICAL | Patched | 2026-07-05 |
| Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)
new CVE-2026-6815
web
Unverified | CVE-2026-6815 | web | HIGH | Unverified | 2026-07-05 |
| BoidCMS — Authenticated File Upload to RCE via Template Injection (CVE-2026-39387)
new CVE-2026-39387
web
Patched | CVE-2026-39387 | web | HIGH | Patched | 2026-07-05 |
| BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
new CVE-2026-7515
web
Unverified | CVE-2026-7515 | web | CRITICAL 9.8 | Unverified | 2026-07-05 |
| ApostropheCMS Import — Malicious Tar Archive Path Traversal (CVE-2026-32731)
new CVE-2026-32731
web
Patched | CVE-2026-32731 | web | HIGH | Patched | 2026-07-05 |
| Apktool Resource Table Path Traversal — Malicious APK Builder (CVE-2026-39973)
new CVE-2026-39973
misc
Patched | CVE-2026-39973 | misc | HIGH | Patched | 2026-07-05 |
| AdonisJS bodyparser Path Traversal to Arbitrary File Write (CVE-2026-21440)
new CVE-2026-21440 (GHSA-gvq6-hvvp-h34h)
web
Patched | CVE-2026-21440 | web | CRITICAL 9.2 | Patched | 2026-07-05 |
| Docker cp Copy-Out Destination Escape via Symlink Race
new None assigned as of 2026-07-03
cloud
Unverified | None assigned as of 2026-07-03 | cloud | MEDIUM | Unverified | 2026-07-03 |
| WinRAR Windows Path Traversal via NTFS Alternate Data Streams (CVE-2025-8088)
new
KEV
RW
EPSS 95% CVE-2025-8088
misc
Patched | CVE-2025-8088 | misc | HIGH 8.4 | Patched | 2026-07-01 |
| Cisco Catalyst SD-WAN Manager Arbitrary File Write (CVE-2026-20262)
new
KEV
EPSS 28% CVE-2026-20262
network
Unverified | CVE-2026-20262 | network | MEDIUM 6.5 | Unverified | 2026-07-01 |
| Ubiquiti UniFi OS Unauthenticated RCE Chain (CVE-2026-34908 / CVE-2026-34909 / CVE-2026-34910)
new
KEV
EPSS 85% CVE-2026-34908, CVE-2026-34909, CVE-2026-34910
network
Patched | CVE-2026-34908, CVE-2026-34909, CVE-2026-34910 | network | CRITICAL 10 | Patched | 2026-06-28 |
| Palo Alto PAN-OS GlobalProtect Unauthenticated RCE (CVE-2024-3400)
new
KEV
RW
EPSS 100% CVE-2024-3400
web
Patched | CVE-2024-3400 | web | CRITICAL 10 | Patched | 2026-05-17 |
| Palo Alto PAN-OS Management Interface Authentication Bypass (CVE-2025-0108)
new
KEV
EPSS 98% CVE-2025-0108
web
Patched | CVE-2025-0108 | web | CRITICAL 9.1 | Patched | 2026-05-16 |
| WinRAR Archive Extraction Path Traversal (CVE-2025-6218)
new
KEV
EPSS 90% CVE-2025-6218
misc
Unverified | CVE-2025-6218 | misc | HIGH | Unverified | 2026-05-15 |