Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Palletsprojects Flask17/7/201917/6/2026
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
ModificadaMedia (6.1)1.2%—Flask-admin Project Flask-admin5/9/201817/6/2026
helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.
ModificadaAlta (7.5)3.9%—Palletsprojects FlaskNetapp Active IQNetapp Hyper Converged InfrastructureNetapp Ontap Select Deploy Utility20/8/201817/6/2026
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability…
ModificadaAlta (7.4)0.82%—Flask-oidc Project Flask-oidc7/10/201617/6/2026
flask-oidc version 0.1.2 and earlier is vulnerable to an open redirect
ModificadaMedia (6.8)2.9%—XENXEN Flask Module14/8/200816/6/2026
Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.