Skip to content
Noroxi

sqlalchemy records

5 published records for vendor sqlalchemy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

5 records
  • SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.

    CriticalCVSS 9.8No exploitEPSS 4%

    sqlalchemy · sqlalchemyFeb 19, 2019

  • CVE-2019-7548
    32Monitor

    SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.

    HighCVSS 7.8No exploitEPSS 2%

    sqlalchemy · sqlalchemyFeb 6, 2019

  • CVE-2012-0805
    31Monitor

    Multiple SQL injection vulnerabilities in SQLAlchemy before 0.7.0b4, as used in Keystone, allow remote attackers to execute arbitrary SQL co

    HighCVSS 7.5No exploitEPSS 3%

    sqlalchemy · sqlalchemyJun 5, 2012

  • Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse.

    HighCVSS 7.5No exploitEPSS 2%

    sqlalchemy · makoSep 7, 2022

  • Mako: Path traversal via double-slash URI prefix in TemplateLookup

    HighCVSS 7.7No exploitEPSS 1%

    sqlalchemy · makoApr 23, 2026