David Lord
17 exploits
Active since Aug 2019
Werkzeug < 2.1.0 - HTTP Request Smuggling via Crafted Request Body
CVSS 9.8
Flask < 2.2.5 and 2.3.0-2.3.2 - Session Cookie Exposure via Caching Proxy
CVSS 7.5
Flask < 2.2.5 and 2.3.0-2.3.2 - Session Cookie Exposure via Caching Proxy
CVSS 7.5
Werkzeug < 3.0.3 - Remote Code Execution via Debugger PIN Bypass
CVSS 7.5
Werkzeug <3.0.6 - DoS
CVSS 7.5
Werkzeug < 3.1.6 - Denial of Service via Windows Device Name Path Handling
CVSS 5.3
Flask < 3.1.3 - Use of Cache Containing Sensitive Information via Session Access
CVSS 4.3
Pallets Werkzeug <0.15.3 - Info Disclosure
CVSS 7.5
Werkzeug < 2.2.3 - Improper Input Validation in Cookie Parsing
CVSS 2.6
Werkzeug < 2.2.3 - Denial of Service via Multipart Form Data Parsing
CVSS 7.5
Jinja < 3.1.4 - Cross-Site Scripting via xmlattr Filter Key Injection
CVSS 5.4
Werkzeug < 3.0.6 - Path Traversal on Windows via UNC Path Handling
CVSS 5.3
Werkzeug <3.0.6 - DoS
CVSS 7.5
Jinja < 3.1.6 - Remote Code Execution via |attr Filter Sandbox Bypass
CVSS 8.8
Flask 3.1.0 - Incorrect Key Order in Fallback Key Configuration
Werkzeug < 3.1.4 - Denial of Service via Windows Device Name Path Handling
CVSS 5.3
Werkzeug < 3.1.5 - Path Traversal via Windows Device Name Bypass
CVSS 5.3