Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Flaskblog
CRITICAL 9.1
CVE-2025-28104
Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
No fix yet
Fix from $2,300
2025-04-21
Flaskblog
MEDIUM 6.4
CVE-2025-28103
Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.
Mitigation only
Fix from $1,600
2025-04-21
Flaskblog
MEDIUM 6.1
CVE-2025-28102
A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inject…
No fix yet
Fix from $1,600
2025-04-21
Flaskblog
MEDIUM 6.5
CVE-2025-28101
An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to delete article titles created by …
No fix yet
Fix from $1,600
2025-04-17