Vulnerabilities > Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DATE CVE VULNERABILITY TITLE RISK
2022-07-11 CVE-2022-31580 Path Traversal vulnerability in Caretakerr-Api Project Caretakerr-Api 20210517
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
caretakerr-api-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31581 Path Traversal vulnerability in Scorelab Openmf
The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
scorelab CWE-22
critical
9.3
2022-07-11 CVE-2022-31582 Path Traversal vulnerability in Videoserver Project Videoserver 20190921
The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
videoserver-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31583 Path Traversal vulnerability in Automatedquizeval Project Automatedquizeval 20200427
The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
automatedquizeval-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31584 Path Traversal vulnerability in S3Label Project S3Label 20190814
The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
s3label-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31585 Path Traversal vulnerability in Home Internet Project Home Internet 20200828
The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
home-internet-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31586 Path Traversal vulnerability in Changepop-Back Project Changepop-Back 20190604
The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
changepop-back-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31587 Path Traversal vulnerability in Kg-Fashion-Chatbot Project Kg-Fashion-Chatbot 20180522
The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
kg-fashion-chatbot-project CWE-22
critical
9.3
2022-07-11 CVE-2022-31588 Path Traversal vulnerability in Testplatform Project Testplatform
The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
network
low complexity
testplatform-project CWE-22
critical
9.3
2022-07-08 CVE-2022-35410 Path Traversal vulnerability in multiple products
mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process.
network
low complexity
0xacab debian CWE-22
7.5