Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.2%—Flask-security Project Flask-security2/8/202217/6/2026
This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an…
ModificadaBaja (2.7)0.74%—Dpgaspar Flask-appbuilder1/8/202217/6/2026
Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not…
ModificadaCrítica (9.3)1.3%—Python-flask-restful-api Project Python-flask-restful-api11/7/202217/6/2026
The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.2%—Flask-yeoman Project Flask-yeoman11/7/202217/6/2026
The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Flask-mongo-skel Project Flask-mongo-skel11/7/202217/6/2026
The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.5%—Helm-flask-celery Project Helm-flask-celery11/7/202217/6/2026
The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.3%—Flask-file-server Project Flask-file-server11/7/202217/6/2026
The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.4%—Flask-mvc Project Flask-mvc11/7/202217/6/2026
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.3)1.5%—Baiduwenkuspider Flaskweb Project Baiduwenkuspider Flaskweb11/7/202217/6/2026
The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaMedia (5.3)1.2%—Flask-session-captcha Project Flask-session-captcha25/4/202217/6/2026
flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.g. by submitting an having an empty form). If implementing users were checking…
ModificadaMedia (6.1)0.97%—Dpgaspar Flask-appbuilder24/3/202217/6/2026
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are currently no known workarounds.
ModificadaMedia (5.3)0.95%—Dpgaspar Flask-appbuilder31/1/202217/6/2026
Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging…
ModificadaAlta (8.8)1.3%—Dpgaspar Flask-appbuilder9/12/202117/6/2026
Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This…
ModificadaAlta (7.5)1.9%—Flask-restx Project Flask-restxFedoraproject Fedora20/9/202117/6/2026
Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.
ModificadaMedia (6.1)0.70%—Dpgaspar Flask-appbuilder8/9/202117/6/2026
Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user to a malicious site. This is an open…
ModificadaCrítica (9.8)2.3%—Talelin Lin-cms-flask16/8/202117/6/2026
Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets.
ModificadaMedia (6.1)1.3%—Talelin Lin-cms-flask16/8/202117/6/2026
Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'.
ModificadaCrítica (9.8)2.0%—Talelin Lin-cms-flask16/8/202117/6/2026
Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'.
ModificadaMedia (6.1)1.1%—Flask-user Project Flask-user5/7/202117/6/2026
This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server…
ModificadaMedia (5.4)0.72%—Flask Unchained Project Flask Unchained11/6/202117/6/2026
This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server…
ModificadaMedia (5.3)3.4%—Dpgaspar Flask-appbuilderApache Airflow7/6/202117/6/2026
Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to…
ModificadaMedia (6.1)2.8%💥 ExploitFlask-security Project Flask-security17/5/202117/6/2026
The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-Security-Too allow redirects after many successful views (e.g. /login) by…
ModificadaCrítica (9.8)7.1%💥 PoCFlask-caching Project Flask-caching13/5/202117/6/2026
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute…
ModificadaAlta (7.4)0.93%—Flask-security-too Project Flask-security-too11/1/202117/6/2026
The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. In Flask-Security-Too from version 3.3.0 and before version 3.4.5, the /login and /change endpoints can…
ModificadaAlta (7.5)4.0%—Flask-cors Project Flask-corsDebian LinuxOpensuse Backports SLEOpensuse Leap31/8/202017/6/2026
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.