pypi

5,089 tracked vulnerabilities.

CVE-2021-40494 CRITICAL
AdaptiveScale LXDUI < 2.1.3 - Hardcoded JWT Secret Key in metadata.py
Sep 03, 2021
CVSS 9.8
EPSS 0.02
CVE-2021-40085 MEDIUM
OpenStack Neutron <18.1.1 - Privilege Escalation
Aug 31, 2021
CVSS 6.5
EPSS 0.02
CVE-2021-39164 LOW
Matrix Synapse < 1.41.1 - Unauthenticated Exposure of Room Membership via History Visibility
Aug 31, 2021
CVSS 3.1
EPSS 0.01
CVE-2021-39163 LOW
Matrix Synapse < 1.41.1 - Unauthenticated Exposure of Sensitive Room Information via Group Endpoints
Aug 31, 2021
CVSS 3.1
EPSS 0.01
CVE-2021-39159 CRITICAL
BinderHub < 0.2.0-n653 - Remote Code Execution via Malicious Input
Aug 25, 2021
CVSS 9.6
EPSS 0.02
CVE-2021-39160 CRITICAL
nbgitpuller 0.9.0-0.10.1 - OS Command Injection via Malicious Link
Aug 25, 2021
CVSS 9.6
EPSS 0.02
CVE-2021-38598 CRITICAL
OpenStack Neutron <16.4.1-18.0.0 - DoS
Aug 23, 2021
CVSS 9.1
EPSS 0.01
CVE-2021-39371 HIGH
Osgeo Owslib < 4.4.5 - XXE
Aug 23, 2021
CVSS 7.5
EPSS 0.02
CVE-2021-39286 MEDIUM
pywb < 2.6.0 - Cross-Site Scripting via Jinja2 Template Autoescaping Bypass
Aug 18, 2021
CVSS 6.1
EPSS 0.01
CVE-2021-35936 MEDIUM
Apache Airflow < 2.1.2 - Info Disclosure
Aug 16, 2021
CVSS 5.3
EPSS 0.04
CVE-2021-23423 MEDIUM
bikeshed < 3.0.0 - Path Traversal via Untrusted Source File Processing
Aug 16, 2021
CVSS 5.5
EPSS 0.01
CVE-2021-23422 HIGH
bikeshed < 3.0.0 - OS Command Injection via Inline Tag Command Metadata
Aug 16, 2021
CVSS 7.8
EPSS 0.01
CVE-2021-37705 CRITICAL
OneFuzz 2.12.0-2.31.0 - Authenticated Origin Validation Error via Multi-Tenant Domain Configuration
Aug 13, 2021
CVSS 10.0
EPSS 0.02
CVE-2021-37690 MEDIUM
TensorFlow 2.3.0-2.3.3 - Use-After-Free in Shape Function Output Handling
Aug 13, 2021
CVSS 6.6
EPSS 0.00
CVE-2021-37692 MEDIUM
TensorFlow 2.5.0-2.5.1 - Use-After-Free in String Tensor Deallocation
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37691 MEDIUM
TensorFlow 2.3.0-2.3.4 - Denial of Service via Division by Zero in LSH Projection
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37687 MEDIUM
TensorFlow 2.3.0-2.3.3 - Out-of-bounds Read in GatherNd and Gather Implementations
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37685 MEDIUM
TensorFlow 2.3.0-2.3.3 - Out-of-bounds Read in TFLite expand_dims.cc
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37684 MEDIUM
TensorFlow 2.3.0-2.3.3 - Divide By Zero in Pooling Implementation
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37683 MEDIUM
TensorFlow 2.3.0-2.3.3 - Denial of Service via Division by Zero in TFLite Div Kernel
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37682 MEDIUM
TensorFlow 2.3.0-2.3.3 - Use of Uninitialized Resource in Quantization Operations
Aug 12, 2021
CVSS 4.4
EPSS 0.00
CVE-2021-37679 HIGH
TensorFlow 2.3.0-2.3.3 - Information Disclosure via RaggedTensor Conversion
Aug 12, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-37678 CRITICAL
TensorFlow 2.3.0-2.3.3 - Remote Code Execution via Keras YAML Model Deserialization
Aug 12, 2021
CVSS 9.3
EPSS 0.00
CVE-2021-37677 MEDIUM
TensorFlow 2.3.0-2.3.3 - Denial of Service via Dequantize Shape Inference
Aug 12, 2021
CVSS 5.5
EPSS 0.00
CVE-2021-37674 MEDIUM
TensorFlow 2.3.0-2.3.3 - Denial of Service via Missing Validation in MaxPoolGrad
Aug 12, 2021
CVSS 5.5
EPSS 0.00