pypi

5,089 tracked vulnerabilities.

CVE-2021-34337 MEDIUM
Mailman Core <3.3.5 - Info Disclosure
Apr 15, 2023
CVSS 6.3
EPSS 0.00
CVE-2021-33926 HIGH
Plone 4.3.2-5.2.4 - Server-Side Request Forgery via RSS Feed Portlet
Feb 17, 2023
CVSS 8.8
EPSS 0.01
CVE-2021-23980 MEDIUM
Mozilla Bleach < 3.3.0 - Cross-Site Scripting via SVG/Math Tags with Strip Comments Disabled
Feb 16, 2023
CVSS 6.1
EPSS 0.00
CVE-2021-4315 MEDIUM
NYUCCL psiTurk <3.2.0 - Template Injection
Jan 28, 2023
CVSS 5.5
EPSS 0.01
CVE-2021-32837 HIGH
mechanize < 0.4.6 - Regular Expression Denial of Service
Jan 17, 2023
CVSS 7.5
EPSS 0.29
CVE-2021-4287 MEDIUM
ReFirm Labs binwalk <2.3.2 - Symlink Following
Dec 27, 2022
CVSS 5.0
EPSS 0.02
CVE-2021-4286 LOW
cocagne pysrp <1.0.16 - Info Disclosure
Dec 27, 2022
CVSS 2.6
EPSS 0.01
CVE-2021-39432 MEDIUM
diplib < 3.1.0 - Double Free
Nov 04, 2022
CVSS 6.5
EPSS 0.01
CVE-2021-3563 HIGH
OpenStack Keystone - Incorrect Authorization via Truncated Application Secret Verification
Aug 26, 2022
CVSS 7.4
EPSS 0.01
CVE-2021-3427 MEDIUM
Deluge < 2.1.0 - Stored Cross-Site Scripting via Crafted Torrent File
Aug 26, 2022
CVSS 6.1
EPSS 0.01
CVE-2021-42521 HIGH
VTK < 9.2.5 - Denial of Service via NULL Pointer Dereference in vtkXMLTreeReader
Aug 25, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-4041 HIGH
ansible-runner < 2.1.0 - Command Injection via Improper Shell Command Escaping
Aug 24, 2022
CVSS 7.8
EPSS 0.00
CVE-2021-3702 MEDIUM
ansible-runner >=2.0.0 <2.1.0 - Race Condition in Temporary Directory Handling
Aug 23, 2022
CVSS 6.3
EPSS 0.00
CVE-2021-3701 MEDIUM
ansible-runner >=2.0.0 <2.1.0 - Incorrect Default Permissions in Temporary Files
Aug 23, 2022
CVSS 6.6
EPSS 0.00
CVE-2021-32862 HIGH
nbconvert < 6.2.0 - Cross-Site Scripting via HTML Notebook Generation
Aug 18, 2022
CVSS 7.5
EPSS 0.01
CVE-2021-23385 MEDIUM
Flask-Security - Open Redirect via Backslash URL Validation Bypass
Aug 02, 2022
CVSS 5.4
EPSS 0.01
CVE-2021-36711 CRITICAL
OctoBot < 0.4.4 - Remote Code Execution via Tentacles Upload
Jul 16, 2022
CVSS 9.8
EPSS 0.15
CVE-2021-37839 MEDIUM
Apache Superset <1.5.1 - Info Disclosure
Jul 06, 2022
CVSS 4.3
EPSS 0.01
CVE-2021-46823 MEDIUM
python-ldap < 3.4.0 - Denial of Service via LDAP Schema Parser ReDoS
Jun 18, 2022
CVSS 6.5
EPSS 0.02
CVE-2021-41945 CRITICAL
httpx < 0.23.0 - Improper Input Validation in URL.copy_with
Apr 28, 2022
CVSS 9.1
EPSS 0.02
CVE-2021-4180 MEDIUM
openstack-tripleo-heat-templates < 11.6.1 - Sensitive Information Exposure via www_authenticate_uri
Mar 23, 2022
CVSS 4.3
EPSS 0.01
CVE-2021-23556 MEDIUM
guake < 3.8.5 - Unauthenticated Remote Code Execution via D-Bus Interface
Mar 17, 2022
CVSS 6.4
EPSS 0.01
CVE-2021-20180 MEDIUM
Ansible < 2.9.18 and 2.8.0a1-2.8.19 - Credential Exposure in Console Log via bitbucket_pipeline_variable Module
Mar 16, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-45848 HIGH
nicotine+ 3.0.3-3.2.1 - Denial of Service via File Path Null Character
Mar 15, 2022
CVSS 7.5
EPSS 0.02
CVE-2021-38296 HIGH
Apache Spark <3.1.2 - Info Disclosure
Mar 10, 2022
CVSS 7.5
EPSS 0.02