Total
443 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-59196 | 1 Pnpm | 1 Pnpm | 2026-07-07 | N/A | 7.1 HIGH |
| pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixed in 10.34.4 and 11.7.0. | |||||
| CVE-2026-59194 | 1 Pnpm | 1 Pnpm | 2026-07-07 | N/A | 7.1 HIGH |
| pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0. | |||||
| CVE-2026-6101 | 2026-07-07 | N/A | 7.5 HIGH | ||
| The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is due to unsafe ZIP file extraction in the ampforwp_save_local_font() function combined with inadequate cleanup that fails to remove nested directories and files. This makes it possible for authenticated attackers, with Author-level access and above, and permissions granted by an Administrator, to write arbitrary files to the server in a web-accessible location, potentially leading to remote code execution on hosts that execute PHP files in the uploads directory. | |||||
| CVE-2026-53648 | 2026-07-07 | N/A | N/A | ||
| FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a deterministic filename-derived path. When an administrator uploads a file for a downloadable product, FOSSBilling stores the file as `md5(<original filename>)` under the uploads directory. Because the stored path depends only on the client-supplied filename, two different downloadable products, or product/order files, uploaded with the same original filename will resolve to the same stored file path. A later upload can overwrite an earlier upload, causing customers or administrators downloading the earlier product to receive the later file instead. Version 0.8.1 patches the issue. Some workarounds are available. Restrict the `servicedownloadable.manage` permission to fully trusted administrators only. As an operational mitigation, ensure downloadable product files use unique filenames before upload. This reduces accidental collisions but does not fully address the underlying issue. | |||||
| CVE-2026-58293 | 1 Microsoft | 1 Edge Chromium | 2026-07-07 | N/A | 8.1 HIGH |
| External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | |||||
| CVE-2026-8921 | 2026-07-06 | N/A | N/A | ||
| External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message. Refer to the ' Security Update for ASUS Business Manager ' section on the ASUS Security Advisory for more information. | |||||
| CVE-2025-65799 | 1 Usememos | 1 Memos | 2026-07-05 | N/A | 4.3 MEDIUM |
| A lack of file name validation or verification in the Attachment service of usememos memos v0.25.2 allows attackers to execute a path traversal. | |||||
| CVE-2026-30284 | 1 Uxgroupllc | 1 Voice Recorder | 2026-07-05 | N/A | 8.6 HIGH |
| An arbitrary file overwrite vulnerability in UXGROUP LLC Voice Recorder v10.0 allows attackers to overwrite critical internal files via the file import process, leading to arbitrary code execution or information exposure. | |||||
| CVE-2026-30282 | 1 Uxgroupllc | 1 Cast To Tv | 2026-07-05 | N/A | 9.0 CRITICAL |
| An arbitrary file overwrite vulnerability in UXGROUP LLC Cast to TV Screen Mirroring v2.2.77 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure. | |||||
| CVE-2026-35080 | 1 Mbs-solutions | 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more | 2026-07-03 | N/A | 8.1 HIGH |
| The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |||||
| CVE-2026-35079 | 1 Mbs-solutions | 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more | 2026-07-03 | N/A | 8.1 HIGH |
| The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |||||
| CVE-2026-35078 | 1 Mbs-solutions | 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more | 2026-07-03 | N/A | 8.1 HIGH |
| The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |||||
| CVE-2026-35077 | 1 Mbs-solutions | 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more | 2026-07-03 | N/A | 8.1 HIGH |
| The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |||||
| CVE-2026-35076 | 1 Mbs-solutions | 19 Double-a Profibus, Double-a X-link, Double-x Can and 16 more | 2026-07-03 | N/A | 8.1 HIGH |
| The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input. | |||||
| CVE-2026-12480 | 2026-07-02 | N/A | 5.5 MEDIUM | ||
| Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1. | |||||
| CVE-2026-55628 | 2026-07-02 | N/A | 5.5 MEDIUM | ||
| In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26. | |||||
| CVE-2026-10816 | 1 Citrix | 2 Netscaler Application Delivery Controller, Netscaler Gateway | 2026-07-02 | N/A | 7.5 HIGH |
| Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled | |||||
| CVE-2026-47214 | 1 Docling | 1 Docling | 2026-07-02 | N/A | 7.1 HIGH |
| Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.94.0, the HTML backend has unsafe URI and path handling. This vulnerability is fixed in 2.94.0. | |||||
| CVE-2026-5821 | 2026-07-02 | N/A | 8.1 HIGH | ||
| The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they are within the uploads directory. The plugin stores backup file paths in the image_optimizer_metadata post meta field and trusts these paths completely when deleting backups on the delete_attachment hook. An authenticated attacker with Author-level access can edit the image_optimizer_metadata post meta on their own attachments via WordPress's Custom Fields interface, injecting arbitrary absolute file paths into the backups array. When the attacker subsequently deletes the attachment, the plugin calls File_System::delete() on each path without validation. This makes it possible for authenticated attackers, with Author-level access and above, to delete arbitrary files on the server within the web server's filesystem permissions, potentially leading to denial of service, data loss, or security degradation. | |||||
| CVE-2025-71333 | 1 Flowiseai | 1 Flowise | 2026-07-01 | N/A | 9.8 CRITICAL |
| Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise. | |||||
