All vulnerabilities
14 / 14
Sort
7.5
CVE-2019-14322DEB
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in …
2019-01-01Pre-auth
EPSS55.5%
pct 98
9.8
CVE-2022-29361CVE
Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perf…
2022-01-01Pre-auth
EPSS7.7%
pct 93
7.5
CVE-2024-34069ANC
Werkzeug is a comprehensive WSGI web application library. The debugger in affected versions of …
2024-01-01Pre-auth
EPSS3.4%
pct 87
7.5
CVE-2019-14806AST
Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness…
2019-01-01Pre-auth
EPSS2.3%
pct 80
7.1
CVE-2016-10516DEB
Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the…
2016-01-01Pre-auth
EPSS2.0%
pct 77
5.4
CVE-2020-28724DEB
Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.
2020-01-01Pre-auth
EPSS1.7%
pct 73
7.5
CVE-2023-25577AST
Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's mu…
2023-01-01Pre-auth
EPSS1.4%
pct 69
6.9
CVE-2024-49767ANC
Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeu…
2024-01-01Pre-auth
EPSS1.1%
pct 61
7.5
CVE-2023-46136AST
Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts wi…
2023-01-01Pre-auth
EPSS1.1%
pct 60
6.3
CVE-2024-49766ANC
Werkzeug is a Web Server Gateway Interface web application library. On Python < 3.11 on Windows…
2024-01-01Pre-auth
EPSS0.8%
pct 51
2.6
CVE-2023-23934AST
Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies…
2023-01-01
EPSS0.6%
pct 43
6.3
CVE-2026-27199ANC
Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_jo…
2026-01-01Pre-auth
EPSS0.6%
pct 41
6.3
CVE-2025-66221ANC
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's sa…
2025-01-01Pre-auth
EPSS0.5%
pct 36
6.3
CVE-2026-21860ANC
Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.5, Werkzeug's sa…
2026-01-01Pre-auth
EPSS0.4%
pct 33
Select a vulnerability on the left to open the preview.