qdrant records
6 published records for vendor qdrant.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-73 External Control of File Name or Path1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-2221No exploit | Path Traversal and Arbitrary File Upload Vulnerability in qdrant/qdrantqdrant · qdrant · CWE-434 | Critical9.8 | — | 1.8% | Apr 10, 2024 |
39Monitor | CVE-2024-3078No exploit | Qdrant Full Snapshot REST API snapshots.rs path traversalqdrant · qdrant · CWE-22 | Critical9.8 | — | 0.9% | Mar 29, 2024 |
36Monitor | CVE-2024-3829Proof of concept | Arbitrary File Read and Write during Snapshot Recovery in qdrant/qdrantqdrant · qdrant · CWE-59 | Critical9.1 | — | 0.9% | Jun 3, 2024 |
35Monitor | CVE-2026-25628No exploit | Qdrant affected by arbitrary file write via `/logger` endpointqdrant · qdrant · CWE-73 | High8.8 | — | 0.6% | Feb 6, 2026 |
30Monitor | CVE-2023-38975No exploit | * Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.qdrant · qdrant · CWE-120 | High7.5 | — | 1.1% | Aug 29, 2023 |
30Monitor | CVE-2024-3584No exploit | Path Traversal in qdrant/qdrantqdrant · qdrant · CWE-20 | High7.5 | — | 0.5% | May 30, 2024 |
- CVE-2024-222140Plan
Path Traversal and Arbitrary File Upload Vulnerability in qdrant/qdrant
CriticalCVSS 9.8No exploitEPSS 2%qdrant · qdrantApr 10, 2024
- CVE-2024-307839Monitor
Qdrant Full Snapshot REST API snapshots.rs path traversal
CriticalCVSS 9.8No exploitEPSS 1%qdrant · qdrantMar 29, 2024
- CVE-2024-382936Monitor
Arbitrary File Read and Write during Snapshot Recovery in qdrant/qdrant
CriticalCVSS 9.1Proof of conceptEPSS 1%qdrant · qdrantJun 3, 2024
- CVE-2026-2562835Monitor
Qdrant affected by arbitrary file write via `/logger` endpoint
HighCVSS 8.8No exploitEPSS 1%qdrant · qdrantFeb 6, 2026
- CVE-2023-3897530Monitor
* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.
HighCVSS 7.5No exploitEPSS 1%qdrant · qdrantAug 29, 2023
- CVE-2024-358430Monitor
Path Traversal in qdrant/qdrant
HighCVSS 7.5No exploitEPSS 1%qdrant · qdrantMay 30, 2024