Vulnerability index

Browse CVEs

71 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.8 CVE-2026-41082 In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. Debian Linux 2.5.1+ Fix from $1,9502026-04-16 MEDIUM 5.5 CVE-2024-53566 An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path … Debian Linux Mitigation only Fix from $1,6002024-12-02 HIGH 7.8 CVE-2024-47742 In the Linux kernel, the following vulnerability has been resolved: firmware_loader: Block path traversal Most firmware names are hardcoded strings… Debian Linux 4.19.323 / 5.4.285+ Fix from $1,9502024-10-21 MEDIUM 5.7 CVE-2022-47951 An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and … Debian Linux 20.0.2 / 23.0.1+ Fix from $1,6002023-01-26 HIGH 7.5 CVE-2020-21365 Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a … Debian Linux after 0.12.5 Fix from $1,9502022-08-15 HIGH 8.1 CVE-2022-31163 TZInfo is a Ruby library that provides access to time zone data and allows times to be converted using time zone rules. Versions prior to 0.36.1, as … Debian Linux 0.3.61 / 1.2.10+ Fix from $1,9502022-07-22 HIGH 7.5 CVE-2022-35410 mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affect… Debian Linux 0.13.0+ Fix from $1,9502022-07-08 CRITICAL 9.8 CVE-2022-1664 Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversa… Dpkg 1.18.26 / 1.19.8+ Fix from $2,3002022-05-26 HIGH 7.5 CVE-2022-30333 KEVEPSS 99% RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by … Debian Linux 6.12+ Fix from $1,9502022-05-09 HIGH 7.5 CVE-2022-29970 Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. Debian Linux 2.2.0+ Fix from $1,9502022-05-02 HIGH 7.5 CVE-2020-29050 SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can… Debian Linux after 3.1.1 Fix from $1,9502022-01-10 CRITICAL 9.8 CVE-2021-3907 OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://example.org/repo/../../etc/cr… Debian Linux 1.3.0+ Fix from $2,3002021-11-11 HIGH 7.8 CVE-2021-42771 Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversa… Debian Linux 2.9.1+ Fix from $1,9502021-10-20 HIGH 8.1 CVE-2021-41072 squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesyst… Debian Linux Patch available Fix from $1,9502021-09-14 HIGH 8.6 CVE-2021-37712 The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution … Debian Linux 1.0.1.1+ Fix from $1,9502021-08-31 HIGH 8.6 CVE-2021-37701 The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution v… Debian Linux 1.0.1.1 / 4.4.16+ Fix from $1,9502021-08-31 HIGH 7.4 CVE-2021-20247 A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or… Debian Linux 1.3.5 / 1.4.1+ Fix from $1,9502021-02-23 MEDIUM 5.3 CVE-2020-35176 In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to on… Debian Linux after 7.8 Fix from $1,6002020-12-12 CRITICAL 9.8 CVE-2020-29600 In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/… Debian Linux after 7.7 Fix from $2,3002020-12-07 CRITICAL 9.8 CVE-2020-25074EPSS 7% The cache action in action/cache.py in MoinMoin through 1.9.10 allows directory traversal through a crafted HTTP request. An attacker who can upload … Debian Linux after 1.9.10 Fix from $2,3002020-11-10 HIGH 7.5 CVE-2019-20916 The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can… Debian Linux 19.2+ Fix from $1,9502020-09-04 HIGH 7.5 CVE-2020-25032 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources bec… Debian Linux 3.0.9+ Fix from $1,9502020-08-31 HIGH 7.5 CVE-2020-24368 Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files th… Debian Linux 2.6.4 / 2.7.4+ Fix from $1,9502020-08-19 HIGH 8.6 CVE-2020-8161 A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory a… Debian Linux 2.2.0+ Fix from $1,9502020-07-02 MEDIUM 6.5 CVE-2020-11652 KEVEPSS 86% An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some meth… Debian Linux 2019.2.4 / 3000.2+ Fix from $1,6002020-04-30 MEDIUM 6.3 CVE-2020-8865EPSS 7% This vulnerability allows remote attackers to execute local PHP files on affected installations of Horde Groupware Webmail Edition 5.2.22. Authentica… Debian Linux Mitigation only Fix from $1,6002020-03-23 MEDIUM 6.5 CVE-2011-4350EPSS 16% Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed. A remote authenticated user could use this flaw to obtain co… Debian Linux No fix yet Fix from $1,6002019-11-26 HIGH 7.5 CVE-2015-1396 A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a pa… Debian Linux 2.7.4+ Fix from $1,9502019-11-25 HIGH 8.6 CVE-2019-10185 It was found that icedtea-web up to and including 1.7.2 and 1.8.2 was vulnerable to a zip-slip attack during auto-extraction of a JAR file. An attack… Debian Linux after 1.7.2 Fix from $1,9502019-07-31 HIGH 8.8 CVE-2019-9858EPSS 19% Remote code execution was discovered in Horde Groupware Webmail 5.2.22 and 5.2.17. Horde/Form/Type.php contains a vulnerable class that handles image… Debian Linux No fix yet Fix from $1,9502019-05-29