CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Description
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-126 · CAPEC-64 · CAPEC-76 · CAPEC-78 · CAPEC-79
CVEs mapped to this weakness (10,395)
page 36 of 520| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-31555 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31554 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31553 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31552 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31551 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31550 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31548 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31547 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31546 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31545 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31544 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31543 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31542 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31541 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31540 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31539 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31538 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31537 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31536 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | ||
| CVE-2022-31535 | Cri | 0.61 | 9.3 | 0.01 | Jul 11, 2022 | The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. |
- risk 0.61cvss 9.3epss 0.01
The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
- risk 0.61cvss 9.3epss 0.01
The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.