Known vulnerabilities in Flask-CORS
Vendor:
Cory Dolphin
Software:
Flask-CORS
Software CPE:
cpe:2.3:a:corydolphin:flask-cors:*:*:*:*:*:*:*:*
Website:
https://github.com/corydolphin
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
6.0.5
6.0.4
6.0.3
6.0.2
6.0.1
6.0.0
5.0.1
5.0.0
4.0.2
4.0.1
4.0.0
3.1.01
3.0.10
3.0.9
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.1.3
2.1.2
2.1.1
2.1.0
2.0.1
2.0.0
1.10.3
1.10.2
1.10.1
1.10.0
1.9.0
1.8.1
1.8.0
1.7.4
1.7.3
1.7.2
1.7.1
1.7.0
1.6.1
1.6.0
1.4.0
1.3.1
1.3.0
1.2.1
1.2.0
1.1.3
1.1.2
1.1.1
1.1
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112142 - Improper Handling of Case Sensitivity CVE-2024-6866 |
CWE-178 | Medium | 6.0.0 | 03.07.2025 |
SB2025070336 SB2025070342 SB2025080147 and 6 more |
||
| #VU112141 - Improper input validation CVE-2024-6844 |
CWE-20 | 6.0.0 | 03.07.2025 |
SB2025070336 SB2025070342 SB2025080147 and 6 more |
|||
| #VU112140 - Security Features CVE-2024-6839 |
CWE-254 | Medium | 6.0.0 | 03.07.2025 |
SB2025070336 SB2025070342 SB2025080147 and 6 more |
||
| #VU96730 - Exposure of sensitive information to an unauthorized actor CVE-2024-6221 |
CWE-200 | Medium | 4.0.2 | 03.09.2024 |
SB2024090356 SB2024092768 SB2024100968 and 5 more |
||
| #VU94747 - Improper Output Neutralization for Logs CVE-2024-1681 |
CWE-117 | Medium | 4.0.1 | 26.07.2024 |
SB2024072606 SB2024072607 SB2024072610 and 7 more |
||
| #VU75215 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-25032 |
CWE-22 | Medium | 3.0.9 | 18.04.2023 |
SB2020083127 SB2023041851 SB2024031227 and 1 more |