Writeup Exploits

54,084 exploits tracked across all sources.

Sort: Activity Stars
CVE-2022-31570 WRITEUP CRITICAL
adriankoczuruek/ceneo-web-scrapper <2021-03-15 - Path Traversal
The adriankoczuruek/ceneo-web-scrapper repository through 2021-03-15 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.8
CVE-2022-31568 WRITEUP CRITICAL
Rexians/rex-web <2022-06-05 - Path Traversal
The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31567 WRITEUP CRITICAL
DSABenchmark/DSAB <2.1 - Path Traversal
The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31566 WRITEUP HIGH
DSAB-local/DSAB <2019-02-18 - Path Traversal
The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 8.6
CVE-2022-31565 WRITEUP CRITICAL
yogson/syrabond <2020-05-25 - Path Traversal
The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31564 WRITEUP CRITICAL
woduq1414/munhak-moa <2022-05-03 - Path Traversal
The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31563 WRITEUP CRITICAL
whmacmac/vprj <2022-04-06 - Path Traversal
The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31562 WRITEUP CRITICAL
Waveyan Internship System <2018-05-22 - Path Traversal
The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31561 WRITEUP CRITICAL
varijkapil13/Sphere_ImageBackend <2019-10-03 - Path Traversal
The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31560 WRITEUP CRITICAL
UncleYiba/photo_tag <2020-08-31 - Path Traversal
The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31559 WRITEUP CRITICAL
tsileo/flask-yeoman <2013-09-13 - Path Traversal
The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31558 WRITEUP CRITICAL
Tooxie/Shiva-Server <0.10.0 - Path Traversal
The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31557 WRITEUP CRITICAL
seveas/golem <2016-05-17 - Path Traversal
The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31556 WRITEUP CRITICAL
rusyasoft/TrainEnergyServer <2017-08-03 - Path Traversal
The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31555 WRITEUP CRITICAL
Romain20100/NurseQuest <2018-02-22 - Path Traversal
The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31554 WRITEUP CRITICAL
rohitnayak/movie-review-sentiment-analysis <2017-05-07 - Path Trave...
The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31553 WRITEUP CRITICAL
rainsoupah/sleep-learner <2021-02-21 - Path Traversal
The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31552 WRITEUP CRITICAL
project-anuvaad/anuvaad-corpus <2020-11-23 - Path Traversal
The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31551 WRITEUP CRITICAL
pleomax00/flask-mongo-skel <2012-11-01 - Path Traversal
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31550 WRITEUP CRITICAL
olmax99/pyathenastack <2019-11-08 - Path Traversal
The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31549 WRITEUP CRITICAL
olmax99/helm-flask-celery <2022-05-25 - Path Traversal
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31548 WRITEUP CRITICAL
nrlakin/homepage <2017-03-06 - Path Traversal
The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31547 WRITEUP CRITICAL
noamezekiel/sphere <2020-05-31 - Path Traversal
The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31546 WRITEUP CRITICAL
nlpweb/glance <2014-06-27 - Path Traversal
The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3
CVE-2022-31545 WRITEUP CRITICAL
ml-inory/ModelConverter <2021-04-26 - Path Traversal
The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVSS 9.3