Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-07-11 CVE-2022-31563 Path Traversal vulnerability in Vprj Project Vprj 20220406
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
vprj-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31564 Path Traversal vulnerability in Munhak Munhak-Moa
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
munhak CWE-22
critical
9.3
2022-07-11 CVE-2022-31565 Path Traversal vulnerability in Syrabond Project Syrabond 20200525
The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
syrabond-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31566 Path Traversal vulnerability in Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
8.6
2022-07-11 CVE-2022-31567 Path Traversal vulnerability in Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark 1.0/2.0/2.1
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
data-stream-algorithm-benchmark-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31568 Path Traversal vulnerability in Rexians Rex-Web 20220605
The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
rexians CWE-22
critical
9.3
2022-07-11 CVE-2022-31570 Path Traversal vulnerability in Ceneo-Web-Scrapper Project Ceneo-Web-Scrapper 20210315
The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
ceneo-web-scrapper-project CWE-22
critical
9.8
2022-07-11 CVE-2022-31571 Path Traversal vulnerability in Python-Flask-Restful-Api Project Python-Flask-Restful-Api 20190916
The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
python-flask-restful-api-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31572 Path Traversal vulnerability in Cockybook Project Cockybook 20150416
The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
cockybook-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31573 Path Traversal vulnerability in Chainer Chainerrl-Visualizer 0.1.1
The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
chainer CWE-22
critical
9.3