Vulnerabilities (CVE)

Filtered by CWE-22
Total 7219 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-31563 1 Vprj Project 1 Vprj 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31562 1 Internshipsystem Project 1 Internshipsystem 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31561 1 Sphere Imagebackend Project 1 Sphere Imagebackend 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31560 1 Photo Tag Project 1 Photo Tag 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31559 1 Flask-yeoman Project 1 Flask-yeoman 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31558 1 Shiva-server Project 1 Shiva-server 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31557 1 Golem Project 1 Golem 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31556 1 Trainenergyserver Project 1 Trainenergyserver 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31555 1 Nurse Quest Project 1 Nurse Quest 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31554 1 Movie-review-sentiment-analysis Project 1 Movie-review-sentiment-analysis 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31553 1 Sleep Learner Project 1 Sleep Learner 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31552 1 Anuvaad-corpus Project 1 Anuvaad-corpus 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31551 1 Flask-mongo-skel Project 1 Flask-mongo-skel 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31550 1 Python Athena Stack Project 1 Python Athena Stack 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31549 1 Helm-flask-celery Project 1 Helm-flask-celery 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31548 1 Homepage Project 1 Homepage 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31547 1 Sphere Project 1 Sphere 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31546 1 Glance Project 1 Glance 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31545 1 Modelconverter Project 1 Modelconverter 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31544 1 Xtomo 1 Robo-tom 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.