Vulnerability index

Browse CVEs

71 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Debian Linux HIGH 7.8
CVE-2026-41082

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Fix: 2.5.1+
Fix from $1,950 2026-04-16
Debian Linux MEDIUM 5.5
CVE-2024-53566

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path …

Mitigation only
Fix from $1,600 2024-12-02
Debian Linux HIGH 7.8
CVE-2024-47742

In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Block path traversal Most firmware names are hardcoded strings…

Fix: 4.19.323 / 5.4.285+
Fix from $1,950 2024-10-21
Debian Linux MEDIUM 5.7
CVE-2022-47951

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and …

Fix: 20.0.2 / 23.0.1+
Fix from $1,600 2023-01-26
Debian Linux HIGH 7.5
CVE-2020-21365

Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a …

Fix: after 0.12.5
Fix from $1,950 2022-08-15
Debian Linux HIGH 8.1
CVE-2022-31163

TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as …

Fix: 0.3.61 / 1.2.10+
Fix from $1,950 2022-07-22
Debian Linux HIGH 7.5
CVE-2022-35410

mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect…

Fix: 0.13.0+
Fix from $1,950 2022-07-08
Dpkg CRITICAL 9.8
CVE-2022-1664

Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa…

Fix: 1.18.26 / 1.19.8+
Fix from $2,300 2022-05-26
Debian Linux HIGH 7.5
CVE-2022-30333 KEVEPSS 99%

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …

Fix: 6.12+
Fix from $1,950 2022-05-09
Debian Linux HIGH 7.5
CVE-2022-29970

Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.

Fix: 2.2.0+
Fix from $1,950 2022-05-02
Debian Linux HIGH 7.5
CVE-2020-29050

SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can…

Fix: after 3.1.1
Fix from $1,950 2022-01-10
Debian Linux CRITICAL 9.8
CVE-2021-3907

OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…

Fix: 1.3.0+
Fix from $2,300 2021-11-11
Debian Linux HIGH 7.8
CVE-2021-42771

Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversa…

Fix: 2.9.1+
Fix from $1,950 2021-10-20
Debian Linux HIGH 8.1
CVE-2021-41072

squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst…

Patch available
Fix from $1,950 2021-09-14
Debian Linux HIGH 8.6
CVE-2021-37712

The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution …

Fix: 1.0.1.1+
Fix from $1,950 2021-08-31
Debian Linux HIGH 8.6
CVE-2021-37701

The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v…

Fix: 1.0.1.1 / 4.4.16+
Fix from $1,950 2021-08-31
Debian Linux HIGH 7.4
CVE-2021-20247

A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or…

Fix: 1.3.5 / 1.4.1+
Fix from $1,950 2021-02-23
Debian Linux MEDIUM 5.3
CVE-2020-35176

In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to on…

Fix: after 7.8
Fix from $1,600 2020-12-12
Debian Linux CRITICAL 9.8
CVE-2020-29600

In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/…

Fix: after 7.7
Fix from $2,300 2020-12-07
Debian Linux CRITICAL 9.8
CVE-2020-25074EPSS 7%

The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload …

Fix: after 1.9.10
Fix from $2,300 2020-11-10
Debian Linux HIGH 7.5
CVE-2019-20916

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can…

Fix: 19.2+
Fix from $1,950 2020-09-04
Debian Linux HIGH 7.5
CVE-2020-25032

An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources bec…

Fix: 3.0.9+
Fix from $1,950 2020-08-31
Debian Linux HIGH 7.5
CVE-2020-24368

Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files th…

Fix: 2.6.4 / 2.7.4+
Fix from $1,950 2020-08-19
Debian Linux HIGH 8.6
CVE-2020-8161

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a…

Fix: 2.2.0+
Fix from $1,950 2020-07-02
Debian Linux MEDIUM 6.5
CVE-2020-11652 KEVEPSS 86%

An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth…

Fix: 2019.2.4 / 3000.2+
Fix from $1,600 2020-04-30
Debian Linux MEDIUM 6.3
CVE-2020-8865EPSS 7%

This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentica…

Mitigation only
Fix from $1,600 2020-03-23
Debian Linux MEDIUM 6.5
CVE-2011-4350EPSS 16%

Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co…

No fix yet
Fix from $1,600 2019-11-26
Debian Linux HIGH 7.5
CVE-2015-1396

A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…

Fix: 2.7.4+
Fix from $1,950 2019-11-25
Debian Linux HIGH 8.6
CVE-2019-10185

It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attack…

Fix: after 1.7.2
Fix from $1,950 2019-07-31
Debian Linux HIGH 8.8
CVE-2019-9858EPSS 19%

Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image…

No fix yet
Fix from $1,950 2019-05-29