Vulnerability index

Browse CVEs

8,911 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Path TraversalCWE-22 × clear
Umbral CRITICAL 9.3
CVE-2022-31533

The decentraminds/umbral repository through 2020-01-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2020-01-15
Fix from $2,300 2022-07-11
Pythonweb CRITICAL 9.3
CVE-2022-31534

The echoleegroup/PythonWeb repository through 2018-10-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafe…

Fix: after 2018-10-31
Fix from $2,300 2022-07-11
Fishtank CRITICAL 9.3
CVE-2022-31535

The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2015-06-24
Fix from $2,300 2022-07-11
Ytdl Sync CRITICAL 9.3
CVE-2022-31536

The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send_file function is used unsafe…

Fix: after 2021-01-02
Fix from $2,300 2022-07-11
Solar System Simulator CRITICAL 9.3
CVE-2022-31537

The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is …

Fix: after 2021-07-26
Fix from $2,300 2022-07-11
Mp M08 Interface CRITICAL 9.3
CVE-2022-31538

The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Flask send_file function is used…

Fix: after 2020-12-10
Fix from $2,300 2022-07-11
Kotekan CRITICAL 9.3
CVE-2022-31539

The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2021.11
Fix from $2,300 2022-07-11
Hin Eng Preprocessing CRITICAL 9.3
CVE-2022-31540

The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the Flask send_file function is …

Fix: after 2019-07-16
Fix from $2,300 2022-07-11
Barry Voice Assistant CRITICAL 9.3
CVE-2022-31541

The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used…

Fix: after 2021-01-18
Fix from $2,300 2022-07-11
Mdweb CRITICAL 9.3
CVE-2022-31542

The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2015-05-07
Fix from $2,300 2022-07-11
Setupbox CRITICAL 9.3
CVE-2022-31543

The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 1.0
Fix from $2,300 2022-07-11
Robo Tom CRITICAL 9.3
CVE-2022-31544

The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 1.5
Fix from $2,300 2022-07-11
Modelconverter CRITICAL 9.3
CVE-2022-31545

The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsaf…

Fix: after 2021-04-26
Fix from $2,300 2022-07-11
Glance CRITICAL 9.3
CVE-2022-31546

The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2014-06-27
Fix from $2,300 2022-07-11
Sphere CRITICAL 9.3
CVE-2022-31547

The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2020-05-31
Fix from $2,300 2022-07-11
Homepage CRITICAL 9.3
CVE-2022-31548

The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2017-03-06
Fix from $2,300 2022-07-11
Helm Flask Celery CRITICAL 9.3
CVE-2022-31549

The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsa…

Fix: after 2022-05-25
Fix from $2,300 2022-07-11
Onyxforum CRITICAL 9.3
CVE-2022-31501

The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2022-05-04
Fix from $2,300 2022-07-11
Wormnest CRITICAL 9.3
CVE-2022-31502

The operatorequals/wormnest repository through 0.4.7 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 0.4.7
Fix from $2,300 2022-07-11
Orchest CRITICAL 9.3
CVE-2022-31503

The orchest/orchest repository before 2022.05.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: 2022.05.0+
Fix from $2,300 2022-07-11
Baiduwenkuspider Flaskweb CRITICAL 9.3
CVE-2022-31504

The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function …

Fix: 2021-11-29+
Fix from $2,300 2022-07-11
Mercadoenlineaback CRITICAL 9.3
CVE-2022-31505

The cheo0/MercadoEnLineaBack repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsa…

Fix: after 2022-05-04
Fix from $2,300 2022-07-11
Opendiamond CRITICAL 9.3
CVE-2022-31506

The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 10.1.1
Fix from $2,300 2022-07-11
Ganga CRITICAL 9.3
CVE-2022-31507

The ganga-devs/ganga repository before 8.5.10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: 8.5.10+
Fix from $2,300 2022-07-11
E Voting CRITICAL 9.3
CVE-2022-31508

The idayrus/evoting repository before 2022-05-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: 2022-05-08+
Fix from $2,300 2022-07-11
Usap Dc Web Submission And Dataset Search CRITICAL 9.3
CVE-2022-31509

The iedadata/usap-dc-website repository through 1.0.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 1.0.1
Fix from $2,300 2022-07-11
Simple Rat CRITICAL 9.3
CVE-2022-31510

The sergeKashkin/Simple-RAT repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafe…

Fix: after 2022-05-03
Fix from $2,300 2022-07-11
Equanimity CRITICAL 9.3
CVE-2022-31511

The AFDudley/equanimity repository through 2014-04-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2014-04-23
Fix from $2,300 2022-07-11
Flask Mvc CRITICAL 9.3
CVE-2022-31512

The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2020-09-14
Fix from $2,300 2022-07-11
Krypton CRITICAL 9.3
CVE-2022-31513

The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 2021-06-03
Fix from $2,300 2022-07-11