Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Jena Fuseki HIGH 7.5
CVE-2026-61372

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F…

Fix: 6.2.0+
Fix from $1,950 2026-08-03
Kyuubi HIGH 8.1
CVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-…

Fix: 1.12.0+
Fix from $1,950 2026-07-31
Zeppelin MEDIUM 6.5
CVE-2026-44615

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not…

Fix: 0.12.1+
Fix from $1,600 2026-07-31
Tika HIGH 7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker…

Fix: 3.3.2+
Fix from $1,950 2026-07-30
Kyuubi CRITICAL 9.8
CVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …

Fix: 1.12.0+
Fix from $2,300 2026-07-30
Mina Sshd HIGH 7.5
CVE-2026-56452

Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The impleme…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Mina Sshd HIGH 7.1
CVE-2026-56623

Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git s…

Fix: 2.19.0+
Fix from $1,950 2026-07-20
Ivy MEDIUM 5.4
CVE-2026-26032

The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repa…

Fix: 2.6.0+
Fix from $1,600 2026-07-15
Openmeetings MEDIUM 6.5
CVE-2026-49488

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenM…

Fix: 9.1.0+
Fix from $1,600 2026-07-14
Apache Airflow Providers Google HIGH 8.1
CVE-2026-49297

Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket …

Fix: 22.2.1+
Fix from $1,950 2026-07-06
Lucene.net HIGH 7.5
CVE-2026-47896

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47897

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Apache Airflow Providers Sftp CRITICAL 9.1
CVE-2026-50203

A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv…

Fix: 5.8.1+
Fix from $2,300 2026-06-17
Apache Airflow Providers Samba MEDIUM 6.5
CVE-2026-49818

The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec…

Fix: 4.12.6+
Fix from $1,600 2026-06-09
Mina Sshd HIGH 7.1
CVE-2026-48827

Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operati…

Fix: 2.18.0+
Fix from $1,950 2026-06-01
Ofbiz MEDIUM 6.1
CVE-2026-31379

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Ofbiz MEDIUM 6.5
CVE-2026-29220

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befor…

Fix: 24.09.06+
Fix from $1,600 2026-05-19
Wicket MEDIUM 6.5
CVE-2026-43975

FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file p…

Fix: 10.9.0+
Fix from $1,600 2026-05-06
Thrift HIGH 7.3
CVE-2026-43870

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in…

Fix: 0.23.0+
Fix from $1,950 2026-05-05
Livy MEDIUM 6.3
CVE-2025-66249

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.…

Fix: 0.9.0+
Fix from $1,600 2026-03-13
Pdfbox MEDIUM 5.3
CVE-2026-23907

This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFil…

Fix: after 3.0.7
Fix from $1,600 2026-03-10
Linkis HIGH 7.5
CVE-2025-29847

A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if…

Fix: 1.8.0+
Fix from $1,950 2026-01-19
Kyuubi HIGH 8.8
CVE-2025-66518

Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and…

Fix: 1.10.3+
Fix from $1,950 2026-01-05
Jena HIGH 7.5
CVE-2025-49656

Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to…

Fix: 5.5.0+
Fix from $1,950 2025-07-21
Doris MEDIUM 5.4
CVE-2024-48019

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in …

Fix: 2.1.8 / 3.0.3+
Fix from $1,600 2025-02-04
Ofbiz CRITICAL 9.1
CVE-2024-36104EPSS 87%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before…

Fix: 18.12.14+
Fix from $2,300 2024-06-04
Ofbiz CRITICAL 9.8
CVE-2024-32113 KEVEPSS 99%

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before …

Fix: 18.12.13+
Fix from $2,300 2024-05-08
Zeppelin MEDIUM 6.5
CVE-2024-31860

Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files…

Fix: 0.11.0+
Fix from $1,600 2024-04-09
Pulsar CRITICAL 9.9
CVE-2024-27317EPSS 57%

In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu…

Fix: 2.10.6 / 2.11.4+
Fix from $2,300 2024-03-12
Ofbiz CRITICAL 9.1
CVE-2024-25065EPSS 48%

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

Fix: 18.12.12+
Fix from $2,300 2024-02-29