Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 3.1% | — | Xiaoyunjie Openvpn-cms-flask | 27/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the component User Creation Endpoint. The manipulation of the argument Username leads to command injection. It is possible to initiate the… | |
| Analizada | Media (6.1) | 0.22% | — | Dpgaspar Flask-appbuilder | 16/5/2025 | 17/6/2026 | Flask-AppBuilder is an application development framework built on top of Flask. Versions prior to 4.6.2 would allow for a malicious unauthenticated actor to perform an open redirect by manipulating the Host header in HTTP requests. Flask-AppBuilder 4.6.2 introduced the `FAB_SAFE_REDIRECT_HOSTS` configuration variable,… | |
| Aplazada | Baja (1.8) | 0.18% | — | ItsdangerousAIPalletsprojects FlaskAI | 13/5/2025 | 17/6/2026 | Flask is a web server gateway interface (WSGI) web application framework. In Flask 3.1.0, the way fallback key configuration was handled resulted in the last fallback key being used for signing, rather than the current signing key. Signing is provided by the `itsdangerous` library. A list of keys can be passed, and it… | |
| Analizada | Crítica (9.1) | 0.40% | — | Dogukanurker Flaskblog | 21/4/2025 | 17/6/2026 | Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input. | |
| Analizada | Media (6.4) | 0.22% | — | Dogukanurker Flaskblog | 21/4/2025 | 17/6/2026 | Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request. | |
| Analizada | Media (6.1) | 0.24% | — | Dogukanurker Flaskblog | 21/4/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost. | |
| Analizada | Media (6.5) | 0.21% | — | Dogukanurker Flaskblog | 17/4/2025 | 17/6/2026 | An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by other users via supplying a crafted POST request. | |
| Aplazada | Alta (7.5) | 0.65% | — | VannaAISnowflakeAIPalletsprojects FlaskAI | 20/3/2025 | 17/6/2026 | Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as `/etc/passwd`, by exploiting the exposed SQL queries through a Python… | |
| Modificada | Alta (7.5) | 0.71% | — | Flask-cors Project Flask-cors | 20/3/2025 | 17/6/2026 | corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as… | |
| Modificada | Media (5.3) | 0.31% | — | Flask-cors Project Flask-cors | 20/3/2025 | 17/6/2026 | A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is passed through the unquote_plus function, which converts the '+' character to a space ' '. This behavior leads to incorrect path normalization,… | |
| Modificada | Media (5.3) | 0.73% | — | Flask-cors Project Flask-cors | 20/3/2025 | 17/6/2026 | corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This mismatch in regex pattern priority allows… | |
| Analizada | Media (5.3) | 0.33% | — | Dpgaspar Flask-appbuilder | 3/3/2025 | 17/6/2026 | Flask-AppBuilder is an application development framework. Prior to 4.5.3, Flask-AppBuilder allows unauthenticated users to enumerate existing usernames by timing the response time from the server when brute forcing requests to login. This vulnerability is fixed in 4.5.3. | |
| Analizada | Media (5.5) | 0.27% | — | Dpgaspar Flask-appbuilder | 4/9/2024 | 17/6/2026 | Flask-AppBuilder is an application development framework. Prior to version 4.5.1, the auth DB login form default cache directives allows browser to locally store sensitive data. This can be an issue on environments using shared computer resources. Version 4.5.1 contains a patch for this issue. If upgrading is not… | |
| Modificada | Alta (7.5) | 0.72% | — | Corydolphin Flask-cors | 18/8/2024 | 17/6/2026 | A vulnerability in corydolphin/flask-cors version 4.0.1 allows the `Access-Control-Allow-Private-Network` CORS header to be set to true by default. This behavior can expose private network resources to unauthorized external access, leading to significant security risks such as data breaches, unauthorized access to… | |
| Aplazada | Crítica (9.8) | 3.4% | — | VannaAIDuckdbAIPalletsprojects FlaskAI | 28/6/2024 | 17/6/2026 | Vanna v0.3.4 is vulnerable to SQL injection in its DuckDB integration exposed to its Flask Web APIs. Attackers can inject malicious SQL training data and generate corresponding queries to write arbitrary files on the victim's file system, such as backdoor.php with contents `<?php system($_GET[0]); ?>`. This can lead… | |
| Modificada | Media (5.3) | 0.58% | — | Corydolphin Flask-cors | 19/4/2024 | 17/6/2026 | corydolphin/flask-cors is vulnerable to log injection when the log level is set to debug. An attacker can inject fake log entries into the log file by sending a specially crafted GET request containing a CRLF sequence in the request path. This vulnerability allows attackers to corrupt log files, potentially covering… | |
| Analizada | Media (6.1) | 0.57% | — | Dpgaspar Flask-appbuilder | 29/2/2024 | 17/6/2026 | Flask-AppBuilder is an application development framework, built on top of Flask. A Cross-Site Scripting (XSS) vulnerability has been discovered on the OAuth login page. An attacker could trick a user to follow a specially crafted URL to the OAuth login page. This URL could inject and execute malicious javascript code… | |
| Analizada | Crítica (9.1) | 0.86% | — | Dpgaspar Flask-appbuilder | 29/2/2024 | 17/6/2026 | Flask-AppBuilder is an application development framework, built on top of Flask. When Flask-AppBuilder is set to AUTH_TYPE AUTH_OID, it allows an attacker to forge an HTTP request, that could deceive the backend into using any requested OpenID service. This vulnerability could grant an attacker unauthorised privilege… | |
| Modificada | Media (5.4) | 0.41% | — | Dogukanurker Flaskblog | 17/1/2024 | 17/6/2026 | flaskBlog is a simple blog app built with Flask. Improper storage and rendering of the `/user/<user>` page allows a user's comments to execute arbitrary javascript code. The html template `user.html` contains the following code snippet to render comments made by a user: `<div class="content"… | |
| Modificada | Alta (7.5) | 0.72% | — | Sujeetkv Flaskcode | 13/1/2024 | 17/6/2026 | An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST request to a /update-resource-data/<file_path> URI (from views.py), allows attackers to write to arbitrary files. | |
| Modificada | Alta (7.5) | 0.80% | — | Sujeetkv Flaskcode | 13/1/2024 | 17/6/2026 | An issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a GET request to a /resource-data/<file_path>.txt URI (from views.py), allows attackers to read arbitrary files. | |
| Modificada | Media (6.1) | 1.1% | — | Flask-security-too Project Flask-security-too | 26/12/2023 | 17/6/2026 | An open redirect vulnerability in the python package Flask-Security-Too <=5.3.2 allows attackers to redirect unsuspecting users to malicious sites via a crafted URL by abusing the ?next parameter on the /login and /register routes. | |
| Modificada | Baja (2.7) | 0.68% | — | Flask-appbuilder Project Flask-appbuilder | 22/6/2023 | 17/6/2026 | Flask-AppBuilder is an application development framework, built on top of Flask. Prior to version 4.3.2, an authenticated malicious actor with Admin privileges, could by adding a special character on the add, edit User forms trigger a database error, this error is surfaced back to this actor on the UI. On certain… | |
| Modificada | Alta (7.5) | 1.3% | — | Palletsprojects Flask | 2/5/2023 | 17/6/2026 | Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxy to other clients. If the proxy also caches `Set-Cookie` headers, it may send one client's `session` cookie to other… | |
| Modificada | Alta (7.5) | 0.63% | — | Dpgaspar Flask-appbuilder | 10/4/2023 | 17/6/2026 | Flask-AppBuilder versions before 4.3.0 lack rate limiting which can allow an attacker to brute-force user credentials. Version 4.3.0 includes the ability to enable rate limiting using `AUTH_RATE_LIMITED = True`, `RATELIMIT_ENABLED = True`, and setting an `AUTH_RATE_LIMIT`. |