Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-58015
A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con…
Enterprise Linux
2.88.1+
HIGH 7.1
CVE-2026-6855
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_…
Instructlab
Mitigation only
MEDIUM 6.3
CVE-2026-0964
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could…
Hardened Images
0.11.4+
HIGH 7.5
CVE-2026-1616
The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack…
Open Security Issue Management
2025.9.0+
MEDIUM 6.5
CVE-2024-4982
A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could disco…
Pagure
5.14.1+
HIGH 7.5
CVE-2024-12088
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t…
Discovery
Mitigation only
HIGH 7.1
CVE-2024-51127
An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
Hornetq
after 2.4.9
MEDIUM 6.5
CVE-2024-9676
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda…
Openshift Container Platform
Patch available
HIGH 8.1
CVE-2024-1132
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali…
Build Of Keycloak
22.0.10 / 24.0.3+
HIGH 7.8
CVE-2024-0406
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a…
Advanced Cluster Security
4.0.0 / 4.18.4+
CRITICAL 9.3
CVE-2024-1485
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i…
Openshift
0.0.0-20240206+
MEDIUM 5.3
CVE-2023-7216
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a…
Enterprise Linux
No fix yet
MEDIUM 6.3
CVE-2023-5115
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make …
Ansible Automation Platform
Mitigation only
MEDIUM 6.5
CVE-2023-5189
A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy …
Ansible Automation Platform
No fix yet
CRITICAL 9.8
CVE-2023-3961
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory…
Storage
4.17.12 / 4.18.8+
HIGH 7.5
CVE-2022-4244
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid…
Integration Camel K
1.10.1 / 3.0.24+
MEDIUM 5.5
CVE-2022-3146
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…
Openstack
Mitigation only
MEDIUM 5.5
CVE-2022-3101
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…
Openstack
Mitigation only
CRITICAL 9.1
CVE-2022-3782EPSS 6%
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a…
Keycloak
Mitigation only
CRITICAL 9.8
CVE-2021-3762
A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w…
Clair
0.4.8 / 0.5.5+
HIGH 7.4
CVE-2021-20218
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using …
Kubernetes Client
4.7.2 / 4.11.2+
HIGH 7.5
CVE-2020-14366
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint…
Keycloak
12.0.0+
HIGH 8.0
CVE-2020-14352
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repo…
Librepo
1.12.1+
MEDIUM 5.2
CVE-2020-10691
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extract…
Ansible Engine
2.9.7+
HIGH 7.5
CVE-2020-1699
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i…
Ceph Storage
Mitigation only
HIGH 8.8
CVE-2020-10696
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious containe…
Openshift Container Platform
1.14.5+
HIGH 7.8
CVE-2020-1737
A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as t…
Ansible Engine
2.7.17 / 2.8.9+
HIGH 7.8
CVE-2015-3151
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of ar…
Automatic Bug Reporting Tool
Patch available
HIGH 7.8
CVE-2019-10167
The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify …
Libvirt
4.10.1 / 5.4.1+
HIGH 7.8
CVE-2019-10168
The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula…
Libvirt
4.10.1 / 5.4.1+