pypi

5,089 tracked vulnerabilities.

CVE-2021-42343 CRITICAL
Dask distributed < 2021.10.0 - Remote Code Execution via External Interface Exposure
Oct 26, 2021
CVSS 9.8
EPSS 0.03
CVE-2021-41127 HIGH
rasa < 2.8.10 - Path Traversal and Arbitrary File Write via Malicious Model Tarball
Oct 21, 2021
CVSS 7.3
EPSS 0.01
CVE-2021-41146 HIGH
qutebrowser 1.7.0-2.4.0 - Remote Code Execution via URL Handler Command Injection
Oct 21, 2021
CVSS 8.8
EPSS 0.01
CVE-2021-42771 HIGH
Babel < 2.9.1 - Remote Code Execution via Locale .dat File Path Traversal
Oct 20, 2021
CVSS 7.8
EPSS 0.01
CVE-2021-41131 HIGH
The Update Framework < 0.18.1 and TUF < 0.19.0 - Path Traversal via Role Name
Oct 19, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-42576 CRITICAL
bluemonday < 1.0.16 and pybluemonday < 0.0.8 - Policy Enforcement Bypass in SELECT STYLE and OPTION Elements
Oct 18, 2021
CVSS 9.8
EPSS 0.02
CVE-2021-41971 HIGH
Apache Superset <= 1.3.0 - Authenticated SQL Injection via Custom URL
Oct 18, 2021
CVSS 8.8
EPSS 0.02
CVE-2021-32609 MEDIUM
Apache Superset <= 1.1 - Stored Cross-Site Scripting in Explore Page Chart Title
Oct 18, 2021
CVSS 5.4
EPSS 0.02
CVE-2021-40720 CRITICAL
Adobe ops-cli < 2.0.5 - Remote Code Execution via Deserialization in Checkout Repo Function
Oct 15, 2021
CVSS 9.8
EPSS 0.09
CVE-2021-41132 CRITICAL
OMERO.web < 5.11.0 - Cross-Site Scripting via Improper HTML Escaping
Oct 14, 2021
CVSS 9.8
EPSS 0.01
CVE-2021-42134 MEDIUM
django-unicorn < 0.36.1 - Cross-Site Scripting
Oct 11, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-40978 HIGH NUCLEI
mkdocs 1.2.2 - Path Traversal via Dev-Server Port 8000
Oct 07, 2021
CVSS 7.5
EPSS 0.15
CVE-2021-42053 MEDIUM
django-unicorn < 0.36.0 - Cross-Site Scripting via Component Name
Oct 07, 2021
CVSS 5.4
EPSS 0.03
CVE-2021-41125 MEDIUM
Scrapy < 1.8.1 - Credential Exposure via HttpAuthMiddleware
Oct 06, 2021
CVSS 5.7
EPSS 0.01
CVE-2021-41121 HIGH
vyperlang/vyper < 0.3.0 - Memory Corruption via Function Call in Literal Struct
Oct 06, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-41122 MEDIUM
vyperlang/vyper < 0.3.0 - Incorrect Calculation in External Function Decimal Argument Validation
Oct 05, 2021
CVSS 4.3
EPSS 0.01
CVE-2021-41124 HIGH
scrapy-splash < 0.8.0 - Credential Exposure via HttpAuthMiddleware
Oct 05, 2021
CVSS 7.4
EPSS 0.01
CVE-2021-41868 CRITICAL
OnionShare 2.3-2.4 - Unauthenticated Arbitrary File Upload via Receive Mode
Oct 04, 2021
CVSS 9.8
EPSS 0.02
CVE-2021-41867 MEDIUM
OnionShare 2.3-2.4 - Unauthenticated Information Disclosure via Chat Feature
Oct 04, 2021
CVSS 5.3
EPSS 0.02
CVE-2021-22557 MEDIUM
SLO Generator < 2.0.1 - Remote Code Execution via YAML File Loading
Oct 04, 2021
CVSS 5.3
EPSS 0.02
CVE-2021-40325 HIGH
Cobbler < 3.3.0 - Authorization Bypass for Settings Modification
Oct 04, 2021
CVSS 7.5
EPSS 0.01
CVE-2021-40324 HIGH
cobbler < 3.3.0 - Arbitrary File Write via upload_log_data
Oct 04, 2021
CVSS 7.5
EPSS 0.69
CVE-2021-40323 CRITICAL NUCLEI
Cobbler < 3.3.0 - Remote Code Execution via XMLRPC Log Poisoning
Oct 04, 2021
CVSS 9.8
EPSS 0.88
CVE-2021-25963 MEDIUM
Shuup 1.6.0-2.10.8 - Reflected Cross-Site Scripting via Error Page
Sep 30, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-25962 HIGH
Shuup 0.4.2-2.10.8 - Code Injection
Sep 29, 2021
CVSS 8.0
EPSS 0.01