CWE-22
High likelihoodImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
9,220 vulnerabilities with CWE-22
CVE-2022-31546
CRITICAL
nlpweb/glance <2014-06-27 - Path Traversal
CVSS 9.3
CVE-2022-31545
CRITICAL
ml-inory/ModelConverter <2021-04-26 - Path Traversal
CVSS 9.3
CVE-2022-31544
CRITICAL
meerstein/rbtm <1.5 - Path Traversal
CVSS 9.3
CVE-2022-31543
CRITICAL
maxtortime/SetupBox <1.0 - Path Traversal
CVSS 9.3
CVE-2022-31542
CRITICAL
Mandoku/mdweb <2015-05-07 - Path Traversal
CVSS 9.3
CVE-2022-31541
CRITICAL
lyubolp/Barry-Voice-Assistant <2021-01-18 - Path Traversal
CVSS 9.3
CVE-2022-31540
CRITICAL
kumardeepak/hin-eng-preprocessing <2019-07-16 - Path Traversal
CVSS 9.3
CVE-2022-31539
CRITICAL
kotekan/kotekan <2021.11 - Path Traversal
CVSS 9.3
CVE-2022-31538
CRITICAL
joaopedro-fg/mp-m08-interface <2020-12-10 - Path Traversal
CVSS 9.3
CVE-2022-31537
CRITICAL
jmcginty15/Solar-system-simulator <2021-07-26 - Path Traversal
CVSS 9.3
CVE-2022-31536
CRITICAL
jaygarza1982/ytdl-sync <2021-01-02 - Path Traversal
CVSS 9.3
CVE-2022-31535
CRITICAL
freefood89/Fishtank <2015-06-24 - Path Traversal
CVSS 9.3
CVE-2022-31534
CRITICAL
echoleegroup/PythonWeb <2018-10-31 - Path Traversal
CVSS 9.3
CVE-2022-31533
CRITICAL
decentraminds/umbral <2020-01-15 - Path Traversal
CVSS 9.3
CVE-2022-31532
CRITICAL
dankolbman/travel_blahg <2016-01-16 - Path Traversal
CVSS 9.3
CVE-2022-31531
CRITICAL
dainst/cilantro <0.0.4 - Path Traversal
CVSS 9.3
CVE-2022-31530
CRITICAL
csm_server < 3.5 - Path Traversal via Flask send_file
CVSS 9.3
CVE-2022-31529
CRITICAL
cinemaproject/monorepo <2021-03-03 - Path Traversal
CVSS 9.3
CVE-2022-31528
CRITICAL
Bonn-Activity-Maps bam-annotation-tool - Path Traversal
CVSS 9.3
CVE-2022-31527
CRITICAL
Wildog/flask-file-server <2020-02-20 - Path Traversal
CVSS 9.3
CVE-2022-31526
CRITICAL
ThundeRatz/ThunderDocs <2020-05-01 - Path Traversal
CVSS 9.3
CVE-2022-31525
CRITICAL
SummaLabs/DLS <0.1.0 - Path Traversal
CVSS 9.3
CVE-2022-31524
CRITICAL
PureStorage-OpenConnect/swagger <1.1.5 - Path Traversal
CVSS 9.3
CVE-2022-31523
CRITICAL
PaddlePaddle/Anakin <0.1.1 - Path Traversal
CVSS 9.3
CVE-2022-31522
CRITICAL
NotVinay/karaokey <2019-12-11 - Path Traversal
CVSS 9.3
Details
Vulnerabilities
9,220
Exploit Likelihood
High