CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Shiva Server Project 1Shiva Server Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Trainenergyserver Project 1Trainenergyserver Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Nurse Quest Project 1Nurse Quest Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Movie Review Sentiment Analysis Project 1Movie Review Sentiment Analysis Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Sleep Learner Project 1Sleep Learner Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Anuvaad Corpus Project 1Anuvaad Corpus Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Flask Mongo Skel Project 1Flask Mongo Skel Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Python Athena Stack Project 1Python Athena Stack Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Helm Flask Celery Project 1Helm Flask Celery Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Homepage Project 1Homepage Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Modelconverter Project 1Modelconverter Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Setupbox Project 1Setupbox Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Barry Voice Assistant Project 1Barry Voice Assistant Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Hin Eng Preprocessing Project 1Hin Eng Preprocessing Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |