🌐
Snyk
security.snyk.io › snyk vulnerability database › pip › flask
flask 1.0.1 vulnerabilities | Snyk
Learn more about known flask 1.0.1 vulnerabilities and licenses detected.
🌐
Medium
medium.com › swlh › hacking-flask-applications-939eae4bffed
Hacking Flask Applications. Executing arbitrary commands using the… | by Vickie Li | The Startup | Medium
February 18, 2020 - Hacking Flask Applications Executing arbitrary commands using the Werkzeug Debugger One of the very first web applications I made was developed using Flask. It was the best choice since it has a lot …
🌐
CVE Details
cvedetails.com › version › 986424 › Flask-user-Project-Flask-user-1.0.1.1.html
Flask-user Project Flask-user 1.0.1.1 security vulnerabilities, CVEs
Flask-user Project Flask-user version 1.0.1.1 security vulnerabilities, CVEs, exploits, vulnerability statistics, CVSS scores and references
🌐
Snyk
snyk.io › snyk vulnerability database › pip › flask
Flask 1.1.1 vulnerabilities | Snyk
Learn more about known Flask 1.1.1 vulnerabilities and licenses detected.
🌐
Vulmon
vulmon.com › home › search results
flask vulnerabilities and exploits
This affects the package Flask-Unchained prior to 0.9.0. When using the the _validate_redirect_url function, it is possible to bypass URL validation and redirect a user to an arbitrary URL by providing multiple back slashes such as \\\evil.com/path.
🌐
Snyk
security.snyk.io › snyk vulnerability database › pip › flask-useful
flask-useful 0.1.dev1 vulnerabilities | Snyk
Learn more about known flask-useful 0.1.dev1 vulnerabilities and licenses detected.
🌐
Snyk
security.snyk.io › snyk vulnerability database › pip
flask | Snyk
Security vulnerabilities and package health score for pip package flask
🌐
Rapid7
rapid7.com › db › modules › exploit › multi › http › werkzeug_debug_rce
Pallete Projects Werkzeug Debugger Remote Code ...
June 28, 2015 - This module will exploit the Werkzeug debug console to put down a Python shell. Werkzeug is included with Flask, but not enabled by default. It is also included in other projects, for example the RunServerPlus extension for Django.
🌐
HackTricks
book.hacktricks.xyz › home › network services pentesting › pentesting web › werkzeug
Werkzeug / Flask Debug - HackTricks
2 days ago - Upon collating all necessary data, the exploit script can be executed to generate the Werkzeug console PIN. The script uses the assembled probably_public_bits and private_bits to create a hash, which then undergoes further processing to produce ...
🌐
Veracode
sca.analysiscenter.veracode.com › vulnerability-database › security › authentication-bypass › python › sid-45684
Authentication Bypass Vulnerability in the flask-appbuilder library | Veracode
flask-appbuilder (flask_appbuilder). flask_appbuilder is vulnerable to Authentication Bypass. The vulnerability is due to the manipulation of authentication requests to deceive the backend into utilizing any specified OpenID service, which allows ...
Find elsewhere
🌐
GitHub
github.com › lokori › flask-vuln
GitHub - lokori/flask-vuln: Pretty vulnerable flask app..
September 29, 2017 - Pretty vulnerable flask app.. Contribute to lokori/flask-vuln development by creating an account on GitHub.
Starred by 22 users
Forked by 12 users
Languages   HTML 63.2% | Python 32.2% | Shell 2.5% | Dockerfile 2.1% | HTML 63.2% | Python 32.2% | Shell 2.5% | Dockerfile 2.1%
🌐
iltosec
iltosec.com › blog › post › exploiting-flask-authentication-and-rce-vulnerabilities-chain-lab-writeup
Exploiting Flask Authentication and RCE Vulnerabilities – Chain Lab Writeup
December 2, 2024 - The reverse shell connected back ... system. By exploiting a Flask cookie vulnerability and combining it with insecure file upload functionality, we were able to gain remote code execution (RCE) on the target system...
🌐
CVE Details
cvedetails.com › cve › CVE-2019-1010083
CVE-2019-1010083 : The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. Th
August 24, 2020 - The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1.
🌐
Netapp
security.netapp.com › advisory › ntap-20230818-0006
CVE-2023-30861 Flask Vulnerability in NetApp Products
NetApp is an industry leader in developing and implementing product security standards. Learn how we can help you maintain the confidentiality, integrity, and availability of your data.
🌐
NIST
nvd.nist.gov › vuln › detail › cve-2025-47278
CVE-2025-47278 Detail - NVD
May 13, 2025 - This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use .gov A .gov website belongs to an official government organization in the United States
🌐
NIST
nvd.nist.gov › vuln › search › results
NVD - Search and Statistics
This is a potential security issue, you are being redirected to https://nvd.nist.gov · Official websites use .gov A .gov website belongs to an official government organization in the United States