Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-07-11 CVE-2022-31560 Path Traversal vulnerability in Photo TAG Project Photo TAG 20200831
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
photo-tag-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31561 Path Traversal vulnerability in Sphere Imagebackend Project Sphere Imagebackend 20191003
The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
sphere-imagebackend-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31562 Path Traversal vulnerability in Internshipsystem Project Internshipsystem 20180522
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
internshipsystem-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31563 Path Traversal vulnerability in Vprj Project Vprj 20220406
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
vprj-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31564 Path Traversal vulnerability in Munhak Munhak-Moa
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
munhak CWE-22
critical
9.3
2022-07-11 CVE-2022-31565 Path Traversal vulnerability in Syrabond Project Syrabond 20200525
The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
syrabond-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31566 Path Traversal vulnerability in Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
8.6
2022-07-11 CVE-2022-31567 Path Traversal vulnerability in Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark 1.0/2.0/2.1
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
data-stream-algorithm-benchmark-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31568 Path Traversal vulnerability in Rexians Rex-Web 20220605
The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
rexians CWE-22
critical
9.3
2022-07-11 CVE-2022-31570 Path Traversal vulnerability in Ceneo-Web-Scrapper Project Ceneo-Web-Scrapper 20210315
The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
ceneo-web-scrapper-project CWE-22
critical
9.8