Qdrant

Qdrant

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 06.02.2026 20:44:13
  • Zuletzt bearbeitet 19.02.2026 17:45:58

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-o...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 03.06.2024 10:15:14
  • Zuletzt bearbeitet 15.10.2025 13:15:43

qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snapshot files to include symlinks, leading to arbitrary file read by adding...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 30.05.2024 13:15:49
  • Zuletzt bearbeitet 10.07.2025 18:21:56

qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoint. By manipulating the `name` parameter through URL encoding, an attacker can upload a file to an ar...

Exploit
  • EPSS 25.53%
  • Veröffentlicht 10.04.2024 17:15:54
  • Zuletzt bearbeitet 14.07.2025 18:27:29

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `snapshot` parameter. This vulnerability allows attackers to upload and ov...

  • EPSS 0.22%
  • Veröffentlicht 29.03.2024 13:15:16
  • Zuletzt bearbeitet 07.05.2025 16:29:10

A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/collection/src/collection/snapshots.rs of the component Full Snapshot REST API. The manipulation leads ...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 29.08.2023 22:15:08
  • Zuletzt bearbeitet 21.11.2024 08:14:33

* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.