Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2019-0191
Apache Karaf kar deployer reads .kar archives and extracts the paths from the "repository/" and "resources/" entries in the zip file. It then writes …
Karaf
4.2.3+
HIGH 7.5
CVE-2018-11789EPSS 7%
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule …
Heron
after 0.17.8
HIGH 8.8
CVE-2018-8009EPSS 8%
Apache Hadoop 3.1.0, 3.0.0-alpha to 3.0.2, 2.9.0 to 2.9.1, 2.8.0 to 2.8.4, 2.0.0-alpha to 2.7.6, 0.23.0 to 0.23.11 is exploitable via the zip slip vu…
Hadoop
after 3.0.2
HIGH 7.5
CVE-2018-11759EPSS 91%
The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) …
Tomcat Jk Connector
after 1.2.44
MEDIUM 5.9
CVE-2018-11762EPSS 5%
In Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input …
Tika
after 1.18
MEDIUM 5.3
CVE-2018-8041EPSS 10%
Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.
Camel
after 2.21.1
MEDIUM 5.5
CVE-2018-8008
Apache Storm version 1.0.6 and earlier, 1.2.1 and earlier, and version 1.1.2 and earlier expose an arbitrary file write vulnerability, that can be ac…
Storm
after 1.2.1
MEDIUM 5.3
CVE-2018-8003
Apache Ambari, versions 1.4.0 to 2.6.1, is susceptible to a directory traversal attack allowing an unauthenticated user to craft an HTTP request whic…
Ambari
after 2.6.1
HIGH 7.5
CVE-2018-1323EPSS 47%
The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-…
Tomcat Jk Connector
after 1.2.42
HIGH 7.5
CVE-2018-1316
The ODE process deployment web service was sensible to deployment messages with forged names. Using a path for the name was allowing directory traver…
Ode
after 1.3.2
MEDIUM 6.5
CVE-2017-15712
Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malici…
Oozie
Mitigation only
HIGH 7.5
CVE-2018-1299
In Apache Allura before 1.8.0, unauthenticated attackers may retrieve arbitrary files through the Allura web application. Some webservers used with A…
Allura
1.8.0+
HIGH 7.5
CVE-2014-0115EPSS 5%
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the…
Storm
Patch available
CRITICAL 9.8
CVE-2016-6795EPSS 8%
In the Convention plugin in Apache Struts 2.3.x before 2.3.31, and 2.5.x before 2.5.5, it is possible to prepare a special URL which will be used for…
Struts
Mitigation only
HIGH 7.5
CVE-2017-3163EPSS 7%
When using the Index Replication feature, Apache Solr nodes can pull index files from a master/leader node using an HTTP API which accepts a file nam…
Solr
after 5.5.3
HIGH 7.5
CVE-2017-7675EPSS 10%
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory tr…
Tomcat
Mitigation only
MEDIUM 6.5
CVE-2016-0784EPSS 56%
Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated a…
Openmeetings
after 3.1.0
HIGH 7.2
CVE-2016-0709EPSS 77%
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticate…
Jetspeed
after 2.3.0
MEDIUM 5.0
CVE-2015-1830EPSS 84%
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows …
Activemq
No fix yet
MEDIUM 5.0
CVE-2011-4367EPSS 33%
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allo…
Myfaces
after 2.1.5
MEDIUM 5.0
CVE-2012-5641EPSS 9%
Directory traversal vulnerability in the partition2 function in mochiweb_util.erl in MochiWeb before 2.4.0, as used in Apache CouchDB before 1.0.4, 1…
Couchdb
after 2.3.2
MEDIUM 5.0
CVE-2012-1089EPSS 5%
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-applicati…
Wicket
Mitigation only
HIGH 9.3
CVE-2010-3450EPSS 11%
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a…
Openoffice
3.3.0+
MEDIUM 6.9
CVE-2010-3689
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privilege…
Openoffice
3.3.0+
MEDIUM 5.0
CVE-2010-3863EPSS 55%
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows …
Shiro
after 1.0.0
MEDIUM 5.8
CVE-2009-2693EPSS 10%
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbit…
Tomcat
Patch available
MEDIUM 5.0
CVE-2008-5515EPSS 19%
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before f…
Tomcat
Patch available
HIGH 9.4
CVE-2008-5518EPSS 36%
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows all…
Geronimo
Patch available
MEDIUM 5.0
CVE-2008-6505EPSS 73%
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary fil…
Struts
Mitigation only
MEDIUM 5.0
CVE-2008-2370EPSS 53%
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization bef…
Tomcat
Patch available