CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mp M08 Interface Project 1Mp M08 Interface Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Solar System Simulator Project 1Solar System Simulator Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Ytdl Sync Project 1Ytdl Sync Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Fishtank Project 1Fishtank Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Pythonweb Project 1Pythonweb Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Travel Blahg Project 1Travel Blahg Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Csm Server Project 1Csm Server Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Monorepo Project 1Monorepo Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Bonn Activity Maps Annotation Tool Project 1Bonn Activity Maps Annotation Tool Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Flask File Server Project 1Flask File Server Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Deep Learning Studio Project 1Deep Learning Studio Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Purestorage 1Pure Swagger Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Karaokey Project 1Karaokey Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Logstash Management Api Project 1Logstash Management Api Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Windmill Project 1Windmill Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |