Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
80 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.2% | — | Flask-security Project Flask-security | 2/8/2022 | 17/6/2026 | This affects all versions of package Flask-Security. When using the get_post_logout_redirect and get_post_login_redirect functions, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an… | |
| Modificada | Baja (2.7) | 0.74% | — | Dpgaspar Flask-appbuilder | 1/8/2022 | 17/6/2026 | Flask-AppBuilder is an application development framework built on top of Flask python framework. In versions prior to 4.1.3 an authenticated Admin user could query other users by their salted and hashed passwords strings. These filters could be made by using partial hashed password strings. The response would not… | |
| Modificada | Crítica (9.3) | 1.3% | — | Python-flask-restful-api Project Python-flask-restful-api | 11/7/2022 | 17/6/2026 | The akashtalole/python-flask-restful-api repository through 2019-09-16 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.2% | — | Flask-yeoman Project Flask-yeoman | 11/7/2022 | 17/6/2026 | The tsileo/flask-yeoman repository through 2013-09-13 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Flask-mongo-skel Project Flask-mongo-skel | 11/7/2022 | 17/6/2026 | The pleomax00/flask-mongo-skel repository through 2012-11-01 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.5% | — | Helm-flask-celery Project Helm-flask-celery | 11/7/2022 | 17/6/2026 | The olmax99/helm-flask-celery repository before 2022-05-25 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.3% | — | Flask-file-server Project Flask-file-server | 11/7/2022 | 17/6/2026 | The Wildog/flask-file-server repository through 2020-02-20 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.4% | — | Flask-mvc Project Flask-mvc | 11/7/2022 | 17/6/2026 | The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.3) | 1.5% | — | Baiduwenkuspider Flaskweb Project Baiduwenkuspider Flaskweb | 11/7/2022 | 17/6/2026 | The ChangeWeDer/BaiduWenkuSpider_flaskWeb repository before 2021-11-29 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (5.3) | 1.2% | — | Flask-session-captcha Project Flask-session-captcha | 25/4/2022 | 17/6/2026 | flask-session-captcha is a package which allows users to extend Flask by adding an image based captcha stored in a server side session. In versions prior to 1.2.1, he `captcha.validate()` function would return `None` if passed no value (e.g. by submitting an having an empty form). If implementing users were checking… | |
| Modificada | Media (6.1) | 0.97% | — | Dpgaspar Flask-appbuilder | 24/3/2022 | 17/6/2026 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. Flask-AppBuilder contains an open redirect vulnerability when using database authentication login page on versions below 3.4.5. This issue is fixed in version 3.4.5. There are currently no known workarounds. | |
| Modificada | Media (5.3) | 0.95% | — | Dpgaspar Flask-appbuilder | 31/1/2022 | 17/6/2026 | Flask-AppBuilder is an application development framework, built on top of the Flask web framework. In affected versions there exists a user enumeration vulnerability. This vulnerability allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging… | |
| Modificada | Alta (8.8) | 1.3% | — | Dpgaspar Flask-appbuilder | 9/12/2021 | 17/6/2026 | Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentication vulnerability in the REST API. The issue allows for a malicious actor with a carefully crafted request to successfully authenticate and gain access to existing protected REST API endpoints. This… | |
| Modificada | Alta (7.5) | 1.9% | — | Flask-restx Project Flask-restxFedoraproject Fedora | 20/9/2021 | 17/6/2026 | Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1. | |
| Modificada | Media (6.1) | 0.70% | — | Dpgaspar Flask-appbuilder | 8/9/2021 | 17/6/2026 | Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-AppBuilder OAuth, an attacker can share a carefully crafted URL with a trusted domain for an application built with Flask-AppBuilder, this URL can redirect a user to a malicious site. This is an open… | |
| Modificada | Crítica (9.8) | 2.3% | — | Talelin Lin-cms-flask | 16/8/2021 | 17/6/2026 | Incorrect Access Control in Lin-CMS-Flask v0.1.1 allows remote attackers to obtain sensitive information and/or gain privileges due to the application not invalidating a user's authentication token upon logout, which allows for replaying packets. | |
| Modificada | Media (6.1) | 1.3% | — | Talelin Lin-cms-flask | 16/8/2021 | 17/6/2026 | Cross Site Scripting (XSS) in Lin-CMS-Flask v0.1.1 allows remote attackers to execute arbitrary code by entering scripts in the the 'Username' parameter of the in component 'app/api/cms/user.py'. | |
| Modificada | Crítica (9.8) | 2.0% | — | Talelin Lin-cms-flask | 16/8/2021 | 17/6/2026 | Improper Authentication in Lin-CMS-Flask v0.1.1 allows remote attackers to launch brute force login attempts without restriction via the 'login' function in the component 'app/api/cms/user.py'. | |
| Modificada | Media (6.1) | 1.1% | — | Flask-user Project Flask-user | 5/7/2021 | 17/6/2026 | This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as /////evil.com/path or \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server… | |
| Modificada | Media (5.4) | 0.72% | — | Flask Unchained Project Flask Unchained | 11/6/2021 | 17/6/2026 | This affects the package Flask-Unchained before 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path. This vulnerability is only exploitable if an alternative WSGI server… | |
| Modificada | Media (5.3) | 3.4% | — | Dpgaspar Flask-appbuilderApache Airflow | 7/6/2021 | 17/6/2026 | Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask-AppBuilder <= 3.2.3. Allows for a non authenticated user to enumerate existing accounts by timing the response time from the server when you are logging in. Upgrade to version 3.3.0 or higher to… | |
| Modificada | Media (6.1) | 2.8% | 💥 Exploit | Flask-security Project Flask-security | 17/5/2021 | 17/6/2026 | The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. All versions of Flask-Security-Too allow redirects after many successful views (e.g. /login) by… | |
| Modificada | Crítica (9.8) | 7.1% | 💥 PoC | Flask-caching Project Flask-caching | 13/5/2021 | 17/6/2026 | The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the cache, and execute… | |
| Modificada | Alta (7.4) | 0.93% | — | Flask-security-too Project Flask-security-too | 11/1/2021 | 17/6/2026 | The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is a independently maintained version of Flask-Security based on the 3.0.0 version of Flask-Security. In Flask-Security-Too from version 3.3.0 and before version 3.4.5, the /login and /change endpoints can… | |
| Modificada | Alta (7.5) | 4.0% | — | Flask-cors Project Flask-corsDebian LinuxOpensuse Backports SLEOpensuse Leap | 31/8/2020 | 17/6/2026 | An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format. |