Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
HIGH 7.5 CVE-2026-58015 A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_con… Enterprise Linux 2.88.1+ Fix from $1,9502026-06-30 HIGH 7.1 CVE-2026-6855 A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_… Instructlab Mitigation only Fix from $1,9502026-04-22 MEDIUM 6.3 CVE-2026-0964 A malicious SCP server can send unexpected paths that could make the client application override local files outside of working directory. This could… Hardened Images 0.11.4+ Fix from $1,6002026-03-26 HIGH 7.5 CVE-2026-1616 The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attack… Open Security Issue Management 2025.9.0+ Fix from $1,9502026-01-29 MEDIUM 6.5 CVE-2024-4982 A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could disco… Pagure 5.14.1+ Fix from $1,6002025-05-12 HIGH 7.5 CVE-2024-12088 A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from t… Discovery Mitigation only Fix from $1,9502025-01-14 HIGH 7.1 CVE-2024-51127 An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information. Hornetq after 2.4.9 Fix from $1,9502024-11-04 MEDIUM 6.5 CVE-2024-9676 A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Builda… Openshift Container Platform Patch available Fix from $1,6002024-10-15 HIGH 8.1 CVE-2024-1132 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a mali… Build Of Keycloak 22.0.10 / 24.0.3+ Fix from $1,9502024-04-17 HIGH 7.8 CVE-2024-0406 A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may a… Advanced Cluster Security 4.0.0 / 4.18.4+ Fix from $1,9502024-04-06 CRITICAL 9.3 CVE-2024-1485 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user i… Openshift 0.0.0-20240206+ Fix from $2,3002024-02-14 MEDIUM 5.3 CVE-2023-7216 A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a… Enterprise Linux No fix yet Fix from $1,6002024-02-05 MEDIUM 6.3 CVE-2023-5115 An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make … Ansible Automation Platform Mitigation only Fix from $1,6002023-12-18 MEDIUM 6.5 CVE-2023-5189 A path traversal vulnerability exists in Ansible when extracting tarballs. An attacker could craft a malicious tarball so that when using the galaxy … Ansible Automation Platform No fix yet Fix from $1,6002023-11-14 CRITICAL 9.8 CVE-2023-3961 A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory… Storage 4.17.12 / 4.18.8+ Fix from $2,3002023-11-03 HIGH 7.5 CVE-2022-4244 A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outsid… Integration Camel K 1.10.1 / 3.0.24+ Fix from $1,9502023-09-25 MEDIUM 5.5 CVE-2022-3146 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2022-3101 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 CRITICAL 9.1 CVE-2022-3782EPSS 6% keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a… Keycloak Mitigation only Fix from $2,3002023-01-13 CRITICAL 9.8 CVE-2021-3762 A directory traversal vulnerability was found in the ClairCore engine of Clair. An attacker can exploit this by supplying a crafted container image w… Clair 0.4.8 / 0.5.5+ Fix from $2,3002022-03-03 HIGH 7.4 CVE-2021-20218 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using … Kubernetes Client 4.7.2 / 4.11.2+ Fix from $1,9502021-03-16 HIGH 7.5 CVE-2020-14366 A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint… Keycloak 12.0.0+ Fix from $1,9502020-11-09 HIGH 8.0 CVE-2020-14352 A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repo… Librepo 1.12.1+ Fix from $1,9502020-08-30 MEDIUM 5.2 CVE-2020-10691 An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extract… Ansible Engine 2.9.7+ Fix from $1,6002020-04-30 HIGH 7.5 CVE-2020-1699 A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i… Ceph Storage Mitigation only Fix from $1,9502020-04-21 HIGH 8.8 CVE-2020-10696 A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious containe… Openshift Container Platform 1.14.5+ Fix from $1,9502020-03-31 HIGH 7.8 CVE-2020-1737 A flaw was found in Ansible 2.7.17 and prior, 2.8.9 and prior, and 2.9.6 and prior when using the Extract-Zip function from the win_unzip module as t… Ansible Engine 2.7.17 / 2.8.9+ Fix from $1,9502020-03-09 HIGH 7.8 CVE-2015-3151 Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of ar… Automatic Bug Reporting Tool Patch available Fix from $1,9502020-01-14 HIGH 7.8 CVE-2019-10167 The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify … Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-08-02 HIGH 7.8 CVE-2019-10168 The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emula… Libvirt 4.10.1 / 5.4.1+ Fix from $1,9502019-08-02