Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-41082
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Debian Linux
2.5.1+
MEDIUM 5.5
CVE-2024-53566
An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path …
Debian Linux
Mitigation only
HIGH 7.8
CVE-2024-47742
In the Linux kernel, the following vulnerability has been resolved:
firmware_loader: Block path traversal
Most firmware names are hardcoded strings…
Debian Linux
4.19.323 / 5.4.285+
MEDIUM 5.7
CVE-2022-47951
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and …
Debian Linux
20.0.2 / 23.0.1+
HIGH 7.5
CVE-2020-21365
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a …
Debian Linux
after 0.12.5
HIGH 8.1
CVE-2022-31163
TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as …
Debian Linux
0.3.61 / 1.2.10+
HIGH 7.5
CVE-2022-35410
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect…
Debian Linux
0.13.0+
CRITICAL 9.8
CVE-2022-1664
Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa…
Dpkg
1.18.26 / 1.19.8+
HIGH 7.5
CVE-2022-30333 KEVEPSS 99%
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by …
Debian Linux
6.12+
HIGH 7.5
CVE-2022-29970
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files.
Debian Linux
2.2.0+
HIGH 7.5
CVE-2020-29050
SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can…
Debian Linux
after 3.1.1
CRITICAL 9.8
CVE-2021-3907
OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr…
Debian Linux
1.3.0+
HIGH 7.8
CVE-2021-42771
Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversa…
Debian Linux
2.9.1+
HIGH 8.1
CVE-2021-41072
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst…
Debian Linux
Patch available
HIGH 8.6
CVE-2021-37712
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution …
Debian Linux
1.0.1.1+
HIGH 8.6
CVE-2021-37701
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v…
Debian Linux
1.0.1.1 / 4.4.16+
HIGH 7.4
CVE-2021-20247
A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or…
Debian Linux
1.3.5 / 1.4.1+
MEDIUM 5.3
CVE-2020-35176
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to on…
Debian Linux
after 7.8
CRITICAL 9.8
CVE-2020-29600
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/…
Debian Linux
after 7.7
CRITICAL 9.8
CVE-2020-25074EPSS 7%
The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload …
Debian Linux
after 1.9.10
HIGH 7.5
CVE-2019-20916
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can…
Debian Linux
19.2+
HIGH 7.5
CVE-2020-25032
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources bec…
Debian Linux
3.0.9+
HIGH 7.5
CVE-2020-24368
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files th…
Debian Linux
2.6.4 / 2.7.4+
HIGH 8.6
CVE-2020-8161
A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a…
Debian Linux
2.2.0+
MEDIUM 6.5
CVE-2020-11652 KEVEPSS 86%
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth…
Debian Linux
2019.2.4 / 3000.2+
MEDIUM 6.3
CVE-2020-8865EPSS 7%
This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentica…
Debian Linux
Mitigation only
MEDIUM 6.5
CVE-2011-4350EPSS 16%
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co…
Debian Linux
No fix yet
HIGH 7.5
CVE-2015-1396
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa…
Debian Linux
2.7.4+
HIGH 8.6
CVE-2019-10185
It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attack…
Debian Linux
after 1.7.2
HIGH 8.8
CVE-2019-9858EPSS 19%
Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image…
Debian Linux
No fix yet