Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2026-7246
This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE r…
Click
8.3.3+
MEDIUM 5.3
CVE-2026-27199
Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames i…
Werkzeug
3.1.6+
MEDIUM 5.3
CVE-2026-21860
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows dev…
Werkzeug
3.1.5+
MEDIUM 5.3
CVE-2025-66221
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows dev…
Werkzeug
3.1.4+
HIGH 8.8
CVE-2024-56201
Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls …
Jinja
3.1.5+
HIGH 7.8
CVE-2024-56326
Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an a…
Jinja
3.1.5+
HIGH 7.5
CVE-2024-49767
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a versi…
Quart
0.19.7 / 3.0.6+
MEDIUM 5.3
CVE-2024-49766
Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //serv…
Werkzeug
3.0.6+
MEDIUM 6.1
CVE-2024-22195
Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject …
Jinja
3.1.3+
HIGH 7.5
CVE-2023-46136
Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an up…
Werkzeug
2.3.8+
HIGH 7.5
CVE-2023-30861
Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one clie…
Flask
2.2.5 / 2.3.2+
HIGH 7.5
CVE-2023-25577
Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited numbe…
Werkzeug
2.2.3+
CRITICAL 9.8
CVE-2022-29361EPSS 8%
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP reques…
Werkzeug
after 2.1.0
MEDIUM 6.1
CVE-2020-28724
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
Werkzeug
0.11.6+
HIGH 7.5
CVE-2019-14806
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.
Werkzeug
0.15.3+
HIGH 7.5
CVE-2019-14322EPSS 56%
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
Werkzeug
0.15.5+
HIGH 7.5
CVE-2019-1010083
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded…
Flask
1.0+
HIGH 8.6
CVE-2016-10745
In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
Jinja
2.8.1+
HIGH 7.5
CVE-2018-1000656
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount o…
Flask
0.12.3+
MEDIUM 6.1
CVE-2016-10516
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used …
Werkzeug
0.11.11+