CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Audio Aligner App Project 1Audio Aligner App Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Shackerpanel Project 1Shackerpanel Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Livro Python Project 1Livro Python Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Realestate Project 1Realestate Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Chainer 1Chainerrl Visualizer Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Cockybook Project 1Cockybook Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Python Flask Restful Api Project 1Python Flask Restful Api Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Ceneo Web Scrapper Project 1Ceneo Web Scrapper Jun 17, 2026 Jul 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Data Stream Algorithm Benchmark Project 1Data Stream Algorithm Benchmark Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Data Stream Algorithm Benchmark Project 1Data Stream Algorithm Benchmark Jun 17, 2026 Jul 11, 2022 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Syrabond Project 1Syrabond Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Internshipsystem Project 1Internshipsystem Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Sphere Imagebackend Project 1Sphere Imagebackend Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Photo Tag Project 1Photo Tag Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Flask Yeoman Project 1Flask Yeoman Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |