Skip to main content

Vendor/product archive

qdrant / qdrant CVEs

Beta · best-effort

6 CVEs tagged to qdrant / qdrant2 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-25628

Published Feb 6, 2026

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-co…

CVSS 8.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2024-3829

Published Jun 3, 2024

qdrant/qdrant version 1.9.0-dev is vulnerable to arbitrary file read and write during the snapshot recovery process. Attackers can exploit this vulnerability by manipulating snaps…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3584

Published May 30, 2024

qdrant/qdrant version 1.9.0-dev is vulnerable to path traversal due to improper input validation in the `/collections/{name}/snapshots/upload` endpoint. By manipulating the `name`…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-2221

Published Apr 10, 2024

qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `/collections/{COLLECTION}/snapshots/upload` endpoint, specifically through the `sn…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-3078

Published Mar 29, 2024

A vulnerability was found in Qdrant up to 1.6.1/1.7.4/1.8.2 and classified as critical. This issue affects some unknown processing of the file lib/collection/src/collection/snapsh…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38975

Published Aug 29, 2023

* Buffer Overflow vulnerability in qdrant v.1.3.2 allows a remote attacker cause a denial of service via the chucnked_vectors.rs component.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1