Vulnerabilities (CVE)

Filtered by CWE-22
Total 8099 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32270 1 Realnetworks 1 Realplayer 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).
CVE-2022-32190 1 Golang 1 Go 2024-11-21 N/A 7.5 HIGH
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.
CVE-2022-31836 1 Beego 1 Beego 2024-11-21 7.5 HIGH 9.8 CRITICAL
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
CVE-2022-31793 2 Arris, Inglorion 13 Bgw210, Bgw210 Firmware, Bgw320 and 10 more 2024-11-21 N/A 7.5 HIGH
do_request in request.c in muhttpd before 1.1.7 allows remote attackers to read arbitrary files by constructing a URL with a single character before a desired path on the filesystem. This occurs because the code skips over the first character when serving files. Arris NVG443, NVG599, NVG589, and NVG510 devices and Arris-derived BGW210 and BGW320 devices are affected.
CVE-2022-31662 3 Linux, Microsoft, Vmware 6 Linux Kernel, Windows, Access Connector and 3 more 2024-11-21 N/A 7.5 HIGH
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files.
CVE-2022-31588 1 Testplatform Project 1 Testplatform 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31587 1 Kg-fashion-chatbot Project 1 Kg-fashion-chatbot 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31586 1 Changepop-back Project 1 Changepop-back 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The unizar-30226-2019-06/ChangePop-Back repository through 2019-06-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31585 1 Home Internet Project 1 Home Internet 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The umeshpatil-dev/Home__internet repository through 2020-08-28 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31584 1 S3label Project 1 S3label 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31583 1 Automatedquizeval Project 1 Automatedquizeval 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The sravaniboinepelli/AutomatedQuizEval repository through 2020-04-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31582 1 Videoserver Project 1 Videoserver 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The shaolo1/VideoServer repository through 2019-09-21 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31581 1 Scorelab 1 Openmf 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The scorelab/OpenMF repository before 2022-05-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31580 1 Caretakerr-api Project 1 Caretakerr-api 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31579 1 Iasset Project 1 Iasset 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The ralphjzhang/iasset repository through 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31578 1 Bt Lnmp Project 1 Bt Lnmp 2024-11-21 5.0 MEDIUM 7.5 HIGH
The piaoyunsoft/bt_lnmp repository through 2019-10-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31577 1 Audio Aligner App Project 1 Audio Aligner App 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31576 1 Shackerpanel Project 1 Shackerpanel 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The heidi-luong1109/shackerpanel repository through 2021-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31575 1 Livro Python Project 1 Livro Python 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The duducosmos/livro_python repository through 2018-06-06 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
CVE-2022-31574 1 Realestate Project 1 Realestate 2024-11-21 6.4 MEDIUM 9.3 CRITICAL
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.