JawadPy
10 exploits
Active since Jun 2021
GNU Mailman 2.1.1-2.1.38 - Unauthenticated Path Traversal via Username Parameter
Python 3.11.0-3.11.4 - Untrusted Search Path via os.path.normpath()
urllib3 <1.26.17, <2.0.5 - Info Disclosure
Bello WordPress Theme < 1.6.0 - SQL Injection via Unsanitized Listing Parameters
Elementor Website Builder 1.5.0-3.1.4 - DOM Cross-Site Scripting via Malicious Hash
Pillow < 9.0.1 - Remote Code Execution via ImageMath.eval Expression Injection
Python < 3.11.4 - URL Blocklist Bypass via Leading Blank Characters in urllib.parse
Flask < 2.2.5 and 2.3.0-2.3.2 - Session Cookie Exposure via Caching Proxy
Werkzeug < 2.3.8 and 3.0.0 - Denial of Service via Crafted Multipart Data
CVSS 8.0
Python < 3.11.4 - URL Blocklist Bypass via Leading Blank Characters in urllib.parse
CVSS 7.5