Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Enterprise Linux HIGH 7.5
CVE-2026-58015

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con…

Fix: 2.88.1+
Fix from $1,950 2026-06-30
Instructlab HIGH 7.1
CVE-2026-6855

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…

Mitigation only
Fix from $1,950 2026-04-22
Hardened Images MEDIUM 6.3
CVE-2026-0964

A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could…

Fix: 0.11.4+
Fix from $1,600 2026-03-26
Open Security Issue Management HIGH 7.5
CVE-2026-1616

The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack…

Fix: 2025.9.0+
Fix from $1,950 2026-01-29
Pagure MEDIUM 6.5
CVE-2024-4982

A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could disco…

Fix: 5.14.1+
Fix from $1,600 2025-05-12
Discovery HIGH 7.5
CVE-2024-12088

A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t…

Mitigation only
Fix from $1,950 2025-01-14
Hornetq HIGH 7.1
CVE-2024-51127

An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.

Fix: after 2.4.9
Fix from $1,950 2024-11-04
Openshift Container Platform MEDIUM 6.5
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda…

Patch available
Fix from $1,600 2024-10-15
Build Of Keycloak HIGH 8.1
CVE-2024-1132

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali…

Fix: 22.0.10 / 24.0.3+
Fix from $1,950 2024-04-17
Advanced Cluster Security HIGH 7.8
CVE-2024-0406

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…

Fix: 4.0.0 / 4.18.4+
Fix from $1,950 2024-04-06
Openshift CRITICAL 9.3
CVE-2024-1485

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i…

Fix: 0.0.0-20240206+
Fix from $2,300 2024-02-14
Enterprise Linux MEDIUM 5.3
CVE-2023-7216

A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…

No fix yet
Fix from $1,600 2024-02-05
Ansible Automation Platform MEDIUM 6.3
CVE-2023-5115

An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make …

Mitigation only
Fix from $1,600 2023-12-18
Ansible Automation Platform MEDIUM 6.5
CVE-2023-5189

A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy …

No fix yet
Fix from $1,600 2023-11-14
Storage CRITICAL 9.8
CVE-2023-3961

A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…

Fix: 4.17.12 / 4.18.8+
Fix from $2,300 2023-11-03
Integration Camel K HIGH 7.5
CVE-2022-4244

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…

Fix: 1.10.1 / 3.0.24+
Fix from $1,950 2023-09-25
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Keycloak CRITICAL 9.1
CVE-2022-3782EPSS 6%

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…

Mitigation only
Fix from $2,300 2023-01-13
Clair CRITICAL 9.8
CVE-2021-3762

A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…

Fix: 0.4.8 / 0.5.5+
Fix from $2,300 2022-03-03
Kubernetes Client HIGH 7.4
CVE-2021-20218

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using …

Fix: 4.7.2 / 4.11.2+
Fix from $1,950 2021-03-16
Keycloak HIGH 7.5
CVE-2020-14366

A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint…

Fix: 12.0.0+
Fix from $1,950 2020-11-09
Librepo HIGH 8.0
CVE-2020-14352

A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repo…

Fix: 1.12.1+
Fix from $1,950 2020-08-30
Ansible Engine MEDIUM 5.2
CVE-2020-10691

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extract…

Fix: 2.9.7+
Fix from $1,600 2020-04-30
Ceph Storage HIGH 7.5
CVE-2020-1699

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i…

Mitigation only
Fix from $1,950 2020-04-21
Openshift Container Platform HIGH 8.8
CVE-2020-10696

A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious containe…

Fix: 1.14.5+
Fix from $1,950 2020-03-31
Ansible Engine HIGH 7.8
CVE-2020-1737

A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as t…

Fix: 2.7.17 / 2.8.9+
Fix from $1,950 2020-03-09
Automatic Bug Reporting Tool HIGH 7.8
CVE-2015-3151

Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of ar…

Patch available
Fix from $1,950 2020-01-14
Libvirt HIGH 7.8
CVE-2019-10167

The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02
Libvirt HIGH 7.8
CVE-2019-10168

The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula…

Fix: 4.10.1 / 5.4.1+
Fix from $1,950 2019-08-02