Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

1,121
CRITICAL
3,545
HIGH
2,893
MEDIUM
199
LOW
8,040 CVEs · Page 103/161
9.3
CVE-2022-31535

The freefood89/Fishtank repository through 2015-06-24 on GitHub allows absolute path traversal because the Flask send_fi

9.3
CVE-2022-31536

The jaygarza1982/ytdl-sync repository through 2021-01-02 on GitHub allows absolute path traversal because the Flask send

9.3
CVE-2022-31537

The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the

9.3
CVE-2022-31538

The joaopedro-fg/mp-m08-interface repository through 2020-12-10 on GitHub allows absolute path traversal because the Fla

9.3
CVE-2022-31539

The kotekan/kotekan repository through 2021.11 on GitHub allows absolute path traversal because the Flask send_file func

9.3
CVE-2022-31540

The kumardeepak/hin-eng-preprocessing repository through 2019-07-16 on GitHub allows absolute path traversal because the

9.3
CVE-2022-31541

The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Fla

9.3
CVE-2022-31542

The mandoku/mdweb repository through 2015-05-07 on GitHub allows absolute path traversal because the Flask send_file fun

9.3
CVE-2022-31543

The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file func

9.3
CVE-2022-31544

The meerstein/rbtm repository through 1.5 on GitHub allows absolute path traversal because the Flask send_file function

9.3
CVE-2022-31545

The ml-inory/ModelConverter repository through 2021-04-26 on GitHub allows absolute path traversal because the Flask sen

9.3
CVE-2022-31546

The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file fun

9.3
CVE-2022-31547

The noamezekiel/sphere repository through 2020-05-31 on GitHub allows absolute path traversal because the Flask send_fil

9.3
CVE-2022-31548

The nrlakin/homepage repository through 2017-03-06 on GitHub allows absolute path traversal because the Flask send_file

9.3
CVE-2022-31549

The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask se

9.3
CVE-2022-31550

The olmax99/pyathenastack repository through 2019-11-08 on GitHub allows absolute path traversal because the Flask send_

9.3
CVE-2022-31551

The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask

9.3
CVE-2022-31552

The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Fl

9.3
CVE-2022-31553

The rainsoupah/sleep-learner repository through 2021-02-21 on GitHub allows absolute path traversal because the Flask se

9.3
CVE-2022-31554

The rohitnayak/movie-review-sentiment-analysis repository through 2017-05-07 on GitHub allows absolute path traversal be

9.3
CVE-2022-31555

The romain20100/nursequest repository through 2018-02-22 on GitHub allows absolute path traversal because the Flask send

9.3
CVE-2022-31556

The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask

9.3
CVE-2022-31557

The seveas/golem repository through 2016-05-17 on GitHub allows absolute path traversal because the Flask send_file func

9.3
CVE-2022-31558

The tooxie/shiva-server repository through 0.10.0 on GitHub allows absolute path traversal because the Flask send_file f

9.3
CVE-2022-31559

The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_fi

9.3
CVE-2022-31560

The uncleYiba/photo_tag repository through 2020-08-31 on GitHub allows absolute path traversal because the Flask send_fi

9.3
CVE-2022-31561

The varijkapil13/Sphere_ImageBackend repository through 2019-10-03 on GitHub allows absolute path traversal because the

9.3
CVE-2022-31562

The waveyan/internshipsystem repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask se

9.3
CVE-2022-31563

The whmacmac/vprj repository through 2022-04-06 on GitHub allows absolute path traversal because the Flask send_file fun

9.3
CVE-2022-31564

The woduq1414/munhak-moa repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_fi

9.3
CVE-2022-31565

The yogson/syrabond repository through 2020-05-25 on GitHub allows absolute path traversal because the Flask send_file f

9.3
CVE-2022-31567

The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file functi

9.3
CVE-2022-31568

The Rexians/rex-web repository through 2022-06-05 on GitHub allows absolute path traversal because the Flask send_file f

9.3
CVE-2022-31571

The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because

9.3
CVE-2022-31572

The ceee-vip/cockybook repository through 2015-04-16 on GitHub allows absolute path traversal because the Flask send_fil

9.3
CVE-2022-31573

The chainer/chainerrl-visualizer repository through 0.1.1 on GitHub allows absolute path traversal because the Flask sen

9.3
CVE-2022-31574

The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask

9.3
CVE-2022-31575

The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask sen

9.3
CVE-2022-31576

The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flas

9.3
CVE-2022-31577

The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the F

9.3
CVE-2022-31579

The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_fil

9.3
CVE-2022-31580

The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flas

9.3
CVE-2022-31581

The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file fu

9.3
CVE-2022-31582

The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_fi

9.3
CVE-2022-31583

The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because t

9.3
CVE-2022-31584

The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_fil

9.3
CVE-2022-31585

The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Fla

9.3
CVE-2022-31586

The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because t

9.3
CVE-2022-31587

The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Fl

9.3
CVE-2022-31588

The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_f

Frequently Asked Questions

What is CWE-22?

CWE-22 (Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-22?

There are 11,337 CVE records associated with CWE-22 in our database. Of these, 1121 are critical severity, 3545 are high severity, and 2893 are medium severity.

How can I protect against CWE-22 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-22 using AI-powered security agents.

Detect CWE-22 Vulnerabilities

CyberStrike's AI agents automatically detect improper limitation of a pathname to a restricted directory (path traversal) vulnerabilities across your infrastructure.

Get Started