Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Click HIGH 7.2
CVE-2026-7246

This CVE record was assigned not following CNA/CVE rules and is not considered a valid vulnerability by the Pallets Click project. The original CVE r…

Fix: 8.3.3+
Fix from $1,950 2026-04-30
Werkzeug MEDIUM 5.3
CVE-2026-27199

Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames i…

Fix: 3.1.6+
Fix from $1,600 2026-02-21
Werkzeug MEDIUM 5.3
CVE-2026-21860

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's safe_join function allows path segments with Windows dev…

Fix: 3.1.5+
Fix from $1,600 2026-01-08
Werkzeug MEDIUM 5.3
CVE-2025-66221

Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows path segments with Windows dev…

Fix: 3.1.4+
Fix from $1,600 2025-11-29
Jinja HIGH 8.8
CVE-2024-56201

Jinja is an extensible templating engine. In versions on the 3.x branch prior to 3.1.5, a bug in the Jinja compiler allows an attacker that controls …

Fix: 3.1.5+
Fix from $1,950 2024-12-23
Jinja HIGH 7.8
CVE-2024-56326

Jinja is an extensible templating engine. Prior to 3.1.5, An oversight in how the Jinja sandboxed environment detects calls to str.format allows an a…

Fix: 3.1.5+
Fix from $1,950 2024-12-23
Quart HIGH 7.5
CVE-2024-49767

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a versi…

Fix: 0.19.7 / 3.0.6+
Fix from $1,950 2024-10-25
Werkzeug MEDIUM 5.3
CVE-2024-49766

Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows, os.path.isabs() does not catch UNC paths like //serv…

Fix: 3.0.6+
Fix from $1,600 2024-10-25
Jinja MEDIUM 6.1
CVE-2024-22195

Jinja is an extensible templating engine. Special placeholders in the template allow writing code similar to Python syntax. It is possible to inject …

Fix: 3.1.3+
Fix from $1,600 2024-01-11
Werkzeug HIGH 7.5
CVE-2023-46136

Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an up…

Fix: 2.3.8+
Fix from $1,950 2023-10-25
Flask HIGH 7.5
CVE-2023-30861

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one clie…

Fix: 2.2.5 / 2.3.2+
Fix from $1,950 2023-05-02
Werkzeug HIGH 7.5
CVE-2023-25577

Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited numbe…

Fix: 2.2.3+
Fix from $1,950 2023-02-14
Werkzeug CRITICAL 9.8
CVE-2022-29361EPSS 8%

Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP reques…

Fix: after 2.1.0
Fix from $2,300 2022-05-25
Werkzeug MEDIUM 6.1
CVE-2020-28724

Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.

Fix: 0.11.6+
Fix from $1,600 2020-11-18
Werkzeug HIGH 7.5
CVE-2019-14806

Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.

Fix: 0.15.3+
Fix from $1,950 2019-08-09
Werkzeug HIGH 7.5
CVE-2019-14322EPSS 56%

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

Fix: 0.15.5+
Fix from $1,950 2019-07-28
Flask HIGH 7.5
CVE-2019-1010083

The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded…

Fix: 1.0+
Fix from $1,950 2019-07-17
Jinja HIGH 8.6
CVE-2016-10745

In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.

Fix: 2.8.1+
Fix from $1,950 2019-04-08
Flask HIGH 7.5
CVE-2018-1000656

The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount o…

Fix: 0.12.3+
Fix from $1,950 2018-08-20
Werkzeug MEDIUM 6.1
CVE-2016-10516

Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used …

Fix: 0.11.11+
Fix from $1,600 2017-10-23