Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Sleep Learner CRITICAL 9.3
CVE-2022-31553

The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsa…

Fix: after 2021-02-21
Fix from $2,300 2022-07-11
Movie Review Sentiment Analysis CRITICAL 9.3
CVE-2022-31554

The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file fun…

Fix: after 2017-05-07
Fix from $2,300 2022-07-11
Nurse Quest CRITICAL 9.3
CVE-2022-31555

The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafe…

Fix: after 2018-02-22
Fix from $2,300 2022-07-11
Trainenergyserver CRITICAL 9.3
CVE-2022-31556

The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used u…

Fix: after 2017-08-03
Fix from $2,300 2022-07-11
Golem CRITICAL 9.3
CVE-2022-31557

The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2016-05-17
Fix from $2,300 2022-07-11
Shiva Server CRITICAL 9.3
CVE-2022-31558

The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 0.10.0
Fix from $2,300 2022-07-11
Flask Yeoman CRITICAL 9.3
CVE-2022-31559

The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2013-09-13
Fix from $2,300 2022-07-11
Photo Tag CRITICAL 9.3
CVE-2022-31560

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2020-08-31
Fix from $2,300 2022-07-11
Sphere Imagebackend CRITICAL 9.3
CVE-2022-31561

The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is u…

Fix: after 2019-10-03
Fix from $2,300 2022-07-11
Internshipsystem CRITICAL 9.3
CVE-2022-31562

The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsa…

Fix: after 2018-05-22
Fix from $2,300 2022-07-11
Vprj CRITICAL 9.3
CVE-2022-31563

The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2022-04-06
Fix from $2,300 2022-07-11
Munhak Moa CRITICAL 9.3
CVE-2022-31564

The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: 2022-05-03+
Fix from $2,300 2022-07-11
Syrabond CRITICAL 9.3
CVE-2022-31565

The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2020-05-25
Fix from $2,300 2022-07-11
Data Stream Algorithm Benchmark HIGH 8.6
CVE-2022-31566

The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2019-02-18
Fix from $1,950 2022-07-11
Data Stream Algorithm Benchmark CRITICAL 9.3
CVE-2022-31567

The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2.1
Fix from $2,300 2022-07-11
Rex Web CRITICAL 9.3
CVE-2022-31568

The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2022-06-05
Fix from $2,300 2022-07-11
Ceneo Web Scrapper CRITICAL 9.8
CVE-2022-31570

The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is…

Fix: after 2021-03-15
Fix from $2,300 2022-07-11
Python Flask Restful Api CRITICAL 9.3
CVE-2022-31571

The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function …

Fix: after 2019-09-16
Fix from $2,300 2022-07-11
Cockybook CRITICAL 9.3
CVE-2022-31572

The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2015-04-16
Fix from $2,300 2022-07-11
Chainerrl Visualizer CRITICAL 9.3
CVE-2022-31573

The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsaf…

Fix: after 0.1.1
Fix from $2,300 2022-07-11
Realestate CRITICAL 9.3
CVE-2022-31574

The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used un…

Fix: after 2018-11-30
Fix from $2,300 2022-07-11
Livro Python CRITICAL 9.3
CVE-2022-31575

The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsaf…

Fix: after 2018-06-06
Fix from $2,300 2022-07-11
Deep Learning Studio CRITICAL 9.3
CVE-2022-31525

The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

No fix yet
Fix from $2,300 2022-07-11
Thunderdocs CRITICAL 9.3
CVE-2022-31526

The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafe…

Fix: after 2020-05-01
Fix from $2,300 2022-07-11
Flask File Server CRITICAL 9.3
CVE-2022-31527

The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsa…

Fix: after 2020-02-20
Fix from $2,300 2022-07-11
Bonn Activity Maps Annotation Tool CRITICAL 9.3
CVE-2022-31528

The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file functio…

Fix: after 2021-08-31
Fix from $2,300 2022-07-11
Monorepo CRITICAL 9.3
CVE-2022-31529

The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafe…

Fix: after 2021-03-03
Fix from $2,300 2022-07-11
Csm Server CRITICAL 9.3
CVE-2022-31530

The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 3.5
Fix from $2,300 2022-07-11
Cilantro CRITICAL 9.3
CVE-2022-31531

The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 0.0.4
Fix from $2,300 2022-07-11
Travel Blahg CRITICAL 9.3
CVE-2022-31532

The dankolbman/travel_blahg repository through 2016-01-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsaf…

Fix: after 2016-01-16
Fix from $2,300 2022-07-11