webargs project records
2 published records for vendor webargs project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2020-7965No exploit | flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input.webargs project · webargs · CWE-352 | High8.8 | — | 0.6% | Jan 29, 2020 |
32Monitor | CVE-2019-9710No exploit | An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.webargs project · webargs · CWE-362 | High8.1 | — | 1.1% | Mar 11, 2019 |
- CVE-2020-796535Monitor
flaskparser.py in Webargs 5.x through 5.5.2 doesn't check that the Content-Type header is application/json when receiving JSON input.
HighCVSS 8.8No exploitEPSS 1%webargs project · webargsJan 29, 2020
- CVE-2019-971032Monitor
An issue was discovered in webargs before 5.1.3, as used with marshmallow and other products.
HighCVSS 8.1No exploitEPSS 1%webargs project · webargsMar 11, 2019