CVE-2019-14322
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 56%
from disclosure to weapon658 days
Published on NVDJul 28
1st PoC+658d
exploitation probability
56%top 1% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
Affected products
n/a · n/apublic PoCs found — 5
exploitdbwww.exploit-db.com/exploits/50101unverifiedgithubgithub.com/sergiovks/CVE-2019-14322★ 1githubgithub.com/faisalfs10x/CVE-2019-14322-scanner★ 1githubgithub.com/faisalfs10x/http-vuln-cve2019-14322.nse★ 1cve_referencepacketstormsecurity.com/files/163398/Pallets-Werkzeug-0.15.4-Path-Traversal.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.