pypi

5,093 tracked vulnerabilities.

CVE-2021-26559 MEDIUM
Apache Airflow 2.0.0 - Improper Access Control in Configurations Endpoint
Feb 17, 2021
CVSS 6.5
EPSS 0.03
CVE-2021-23338 MEDIUM
qlib < 0.7.0 - Remote Code Execution via Unsafe YAML Deserialization
Feb 15, 2021
CVSS 6.6
EPSS 0.04
CVE-2021-21240 HIGH
httplib2 < 0.19.0 - Denial of Service via Malicious WWW-Authenticate Header
Feb 08, 2021
CVSS 7.5
EPSS 0.04
CVE-2021-26722 MEDIUM
LinkedIn Oncall < 1.4.0 - Reflected Cross-Site Scripting via Search Bar
Feb 05, 2021
CVSS 6.1
EPSS 0.03
CVE-2021-3281 MEDIUM
Django <2.2.18-3.0.12-3.1.6 - Path Traversal
Feb 02, 2021
CVSS 5.3
EPSS 0.08
CVE-2021-21239 MEDIUM
PySAML2 <6.5.0 - Improper Signature Verification
Jan 21, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-21238 MEDIUM
PySAML2 < 6.5.0 - Improper Verification of Cryptographic Signature via XML Signature Wrapping
Jan 21, 2021
CVSS 6.5
EPSS 0.01
CVE-2021-3028 CRITICAL
git-big-picture < 1.0.0 - Remote Code Execution via Branch Name Handling
Jan 13, 2021
CVSS 9.8
EPSS 0.03
CVE-2021-21241 HIGH
Flask-Security-Too 3.3.0-3.4.5 - Cross-Site Request Forgery via Unprotected GET Requests
Jan 11, 2021
CVSS 7.4
EPSS 0.01
CVE-2021-3116 HIGH
before_upstream_connection <2.3.1 - Info Disclosure
Jan 11, 2021
CVSS 7.5
EPSS 0.02
CVE-2021-21236 MEDIUM
CairoSVG < 2.5.1 - Regular Expression Denial of Service via Malicious SVG Processing
Jan 06, 2021
CVSS 5.7
EPSS 0.01
CVE-2020-36962 CRITICAL
Tendenci 12.3.1 - CSV Formula Injection via Contact Form Message Field
Jan 28, 2026
CVSS 9.8
EPSS 0.11
CVE-2020-35141 HIGH
Faucet SDN Ryu 4.34 - Denial of Service via OFPQueueGetConfigReply Infinite Loop
Aug 11, 2023
CVSS 7.5
EPSS 0.01
CVE-2020-35139 HIGH
Faucet SDN Ryu 4.34 - Denial of Service via OFPBundleCtrlMsg Infinite Loop
Aug 11, 2023
CVSS 7.5
EPSS 0.01
CVE-2020-26710 HIGH
easy-parse 0.1.1 - XML External Entity Injection via Crafted XML File
Jun 29, 2023
CVSS 7.5
EPSS 0.01
CVE-2020-26709 HIGH
py-xml 1.0 - XML External Entity Injection via Crafted XML File
Jun 29, 2023
CVSS 7.5
EPSS 0.01
CVE-2020-26708 HIGH
requests-xml 0.2.3 - XML External Entity Injection
Jun 29, 2023
CVSS 7.5
EPSS 0.01
CVE-2020-6817 HIGH
bleach < 3.1.4 - Regular Expression Denial of Service via Style Attribute Parsing
Feb 16, 2023
CVSS 7.5
EPSS 0.01
CVE-2020-36660 MEDIUM
paxswill EVE Ship Replacement Program <0.12.11 - Info Disclosure
Feb 06, 2023
CVSS 4.3
EPSS 0.01
CVE-2020-26705 CRITICAL
Easy-XML 0.5.0 - XML External Entity Disclosure or Denial of Service
Oct 31, 2021
CVSS 9.1
EPSS 0.01
CVE-2020-19003 MEDIUM
Gate One 1.2.0 - Authentication Bypass via Origin Verification Spoofing
Oct 06, 2021
CVSS 5.3
EPSS 0.01
CVE-2020-23478 HIGH
Leo Editor < 6.3 - Regular Expression Denial of Service in Dart Importer
Sep 22, 2021
CVSS 7.5
EPSS 0.01
CVE-2020-19002 MEDIUM
Mezzanine 4.3.1 - Stored Cross-Site Scripting via Blog Post Description Field
Aug 27, 2021
CVSS 6.1
EPSS 0.01
CVE-2020-19001 CRITICAL
Simiki <1.6.2.1 - Command Injection
Aug 27, 2021
CVSS 9.8
EPSS 0.04
CVE-2020-19000 MEDIUM
simiki < 1.6.2.2 - Cross-Site Scripting in generators.py
Aug 27, 2021
CVSS 6.1
EPSS 0.01