Vulnerabilities (CVE)

Filtered by CWE-22
Total 6545 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31531 1 Dainst 1 Cilantro 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The dainst/cilantro repository through 0.0.4 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31530 1 Csm Server Project 1 Csm Server 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The csm-aut/csm repository through 3.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31529 1 Monorepo Project 1 Monorepo 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The cinemaproject/monorepo repository through 2021-03-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31528 1 Bonn Activity Maps Annotation Tool Project 1 Bonn Activity Maps Annotation Tool 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The bonn-activity-maps/bam_annotation_tool repository through 2021-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31527 1 Flask-file-server Project 1 Flask-file-server 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31526 1 Thunderatz 1 Thunderdocs 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The ThundeRatz/ThunderDocs repository through 2020-05-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31525 1 Deep Learning Studio Project 1 Deep Learning Studio 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The SummaLabs/DLS repository through 0.1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31524 1 Purestorage 1 Pure Swagger 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31523 1 Paddlepaddle 1 Anakin 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The PaddlePaddle/Anakin repository through 0.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31522 1 Karaokey Project 1 Karaokey 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The NotVinay/karaokey repository through 2019-12-11 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31521 1 Mosaic Project 1 Mosaic 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31520 1 Logstash-management-api Project 1 Logstash-management-api 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31519 1 Windmill Project 1 Windmill 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Lukasavicus/WindMill repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31518 1 Python-recipe-database Project 1 Python-recipe-database 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31517 1 Mercury Sample Manager Project 1 Mercury Sample Manager 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The HolgerGraef/MSM repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31516 1 Harveyzyh Python Project 1 Harveyzyh Python 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Harveyzyh/Python repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31515 1 Carceresbe Project 1 Carceresbe 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Delor4/CarceresBE repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31514 1 Fan Platform Project 1 Fan Platform 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Caoyongqi912/Fan_Platform repository through 2021-04-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31513 1 Krypton Project 1 Krypton 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The BolunHan/Krypton repository through 2021-06-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31512 1 Flask-mvc Project 1 Flask-mvc 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.