Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Agendaless

First CVE: Dec 20, 2019Active for: 7 yearsTotal CVEs: 10
33.1
VTI Score
Medium

Agendaless maintains a focused portfolio of Python web infrastructure components, most notably the Waitress application server and Pyramid web framework, which serve as foundational elements in many Python-based deployments. The vulnerability profile centers on a recurring set of HTTP-handling and concurrency issues—including HTTP request smuggling, race conditions, path traversal, and resource-lifecycle defects—that reflect the complexity of correctly implementing HTTP semantics and thread-safe request processing in a high-concurrency server. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Agendaless over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2019
6 years ago
Most Recent CVE
Oct 29, 2024
636 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-16789HIGH
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed different
Dec 26, 20198.227NONO
CVE-2022-24761HIGH
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP
Mar 17, 20227.526NONO
CVE-2019-16785HIGH
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a reci
Dec 20, 20197.526NONO
CVE-2019-16786HIGH
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Con
Dec 20, 20197.525NONO
CVE-2019-16792HIGH
Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unabl
Jan 22, 20207.524NONO
CVE-2024-49769HIGH
Waitress is a Web Server Gateway Interface server for Python 2 and 3. When a remote client closes the connection before waitress has had the opportunity to call getpeername() waitr
Oct 29, 20247.521NONO
CVE-2024-49768MEDIUM
Waitress is a Web Server Gateway Interface server for Python 2 and 3. A remote client may send a request that is exactly recv_bytes (defaults to 8192) long, followed by a secondary
Oct 29, 20244.820NONO
CVE-2020-5236MEDIUM
Waitress version 1.4.2 allows a DOS attack When waitress receives a header that contains invalid characters. When a header like "Bad-header: xxxxxxxxxxxxxxx\x10" is received, it wi
Feb 4, 20206.518NONO
CVE-2023-40587MEDIUM
Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view
Aug 25, 20235.317NONO
CVE-2022-31015MEDIUM
Waitress is a Web Server Gateway Interface server for Python 2 and 3. Waitress versions 2.1.0 and 2.1.1 may terminate early due to a thread closing a socket while the main thread i
May 31, 20225.917NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
40%
60%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Agendaless.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Agendaless — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Agendaless's Products

View all 1 CNAs →

Top CWEs