Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-61372 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F… Jena Fuseki 6.2.0+ Fix from $1,9502026-08-03 HIGH 8.1 CVE-2026-62391 The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-… Kyuubi 1.12.0+ Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-44615 Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not… Zeppelin 0.12.1+ Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-66755 Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker… Tika 3.3.2+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-56452 Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The impleme… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-56623 Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git s… Mina Sshd 2.19.0+ Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-26032 The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a packager.xml file. This repa… Ivy 2.6.0+ Fix from $1,6002026-07-15 MEDIUM 6.5 CVE-2026-49488 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OpenMeetings. This issue affects Apache OpenM… Openmeetings 9.1.0+ Fix from $1,6002026-07-14 HIGH 8.1 CVE-2026-49297 Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket … Apache Airflow Providers Google 22.2.1+ Fix from $1,9502026-07-06 HIGH 7.5 CVE-2026-47896 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 HIGH 7.5 CVE-2026-47897 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.1 CVE-2026-50203 A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv… Apache Airflow Providers Sftp 5.8.1+ Fix from $2,3002026-06-17 MEDIUM 6.5 CVE-2026-49818 The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an objec… Apache Airflow Providers Samba 4.12.6+ Fix from $1,6002026-06-09 HIGH 7.1 CVE-2026-48827 Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operati… Mina Sshd 2.18.0+ Fix from $1,9502026-06-01 MEDIUM 6.1 CVE-2026-31379 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('P… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-29220 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: befor… Ofbiz 24.09.06+ Fix from $1,6002026-05-19 MEDIUM 6.5 CVE-2026-43975 FolderUploadsFileManager in Apache Wicket does not validate or sanitize the uploadFieldId parameter or the clientFileName before constructing file p… Wicket 10.9.0+ Fix from $1,6002026-05-06 HIGH 7.3 CVE-2026-43870 Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in… Thrift 0.23.0+ Fix from $1,9502026-05-05 MEDIUM 6.3 CVE-2025-66249 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Livy. This issue affects Apache Livy: from 0.… Livy 0.9.0+ Fix from $1,6002026-03-13 MEDIUM 5.3 CVE-2026-23907 This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFil… Pdfbox after 3.0.7 Fix from $1,6002026-03-10 HIGH 7.5 CVE-2025-29847 A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if… Linkis 1.8.0+ Fix from $1,9502026-01-19 HIGH 8.8 CVE-2025-66518 Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allow.list and… Kyuubi 1.10.3+ Fix from $1,9502026-01-05 HIGH 7.5 CVE-2025-49656 Users with administrator access can create databases files outside the files area of the Fuseki server. This issue affects Apache Jena version up to… Jena 5.5.0+ Fix from $1,9502025-07-21 MEDIUM 5.4 CVE-2024-48019 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in … Doris 2.1.8 / 3.0.3+ Fix from $1,6002025-02-04 CRITICAL 9.1 CVE-2024-36104EPSS 87% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before… Ofbiz 18.12.14+ Fix from $2,3002024-06-04 CRITICAL 9.8 CVE-2024-32113 KEVEPSS 99% Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz.This issue affects Apache OFBiz: before … Ofbiz 18.12.13+ Fix from $2,3002024-05-08 MEDIUM 6.5 CVE-2024-31860 Improper Input Validation vulnerability in Apache Zeppelin. By adding relative path indicators(E.g ..), attackers can see the contents for any files… Zeppelin 0.11.0+ Fix from $1,6002024-04-09 CRITICAL 9.9 CVE-2024-27317EPSS 57% In Pulsar Functions Worker, authenticated users can upload functions in jar or nar files. These files, essentially zip files, are extracted by the Fu… Pulsar 2.10.6 / 2.11.4+ Fix from $2,3002024-03-12 CRITICAL 9.1 CVE-2024-25065EPSS 48% Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue. Ofbiz 18.12.12+ Fix from $2,3002024-02-29