CWE-22
9,575 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVEs (9,575)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Python Recipe Database Project 1Python Recipe Database Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Mercury Sample Manager Project 1Mercury Sample Manager Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Harveyzyh Python Project 1Harveyzyh Python Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Carceresbe Project 1Carceresbe Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Fan Platform Project 1Fan Platform Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Flask Mvc Project 1Flask Mvc Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Equanimity Project 1Equanimity Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Simple Rat Project 1Simple Rat Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Iedadata 1Usap Dc Web Submission And Dataset Search Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Mercadoenlineaback Project 1Mercadoenlineaback Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Baiduwenkuspider Flaskweb Project 1Baiduwenkuspider Flaskweb Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Wormnest Project 1Wormnest Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
1Onyxforum Project 1Onyxforum Jun 17, 2026 Jul 11, 2022 N/A· v4 9.3 CRITICAL· v3 6.4 MEDIUM· v2 The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
20xacab Debian2Debian Linux Mat2Jun 17, 2026 Jul 8, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive informati...Show more |
A path traversal vulnerability in loader.php of CWP v0.9.8.1122 allows attackers to execute arbitrary code via a crafted POST request. |