pypi

5,093 tracked vulnerabilities.

CVE-2020-7937 MEDIUM
Plone 5.0-5.2.1 - Stored Cross-Site Scripting in Title Field
Jan 23, 2020
CVSS 5.4
EPSS 0.01
CVE-2020-7936 MEDIUM
Plone 4.0-5.2.1 - Open Redirect via Login Form
Jan 23, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-6173 MEDIUM
The Update Framework 0.7.2-0.12.1 - Uncontrolled Resource Consumption
Jan 14, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-5390 HIGH
PySAML2 < 5.0.0 - Improper Verification of Cryptographic Signature via XML Signature Wrapping
Jan 13, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-5313 HIGH
Pillow < 6.2.2 - Out-of-bounds Read in FLI Buffer Handling
Jan 03, 2020
CVSS 7.1
EPSS 0.03
CVE-2020-5312 CRITICAL
Pillow < 6.2.2 - Buffer Overflow in PCX P Mode Decoder
Jan 03, 2020
CVSS 9.8
EPSS 0.04
CVE-2020-5311 CRITICAL
Pillow < 6.2.2 - Buffer Overflow in SGI Image Decoder
Jan 03, 2020
CVSS 9.8
EPSS 0.04
CVE-2020-5310 HIGH
Pillow < 6.2.2 - Integer Overflow in TIFF Decoding
Jan 03, 2020
CVSS 8.8
EPSS 0.02
CVE-2019-19450 CRITICAL
ReportLab < 3.5.31 - Remote Code Execution via Unichar Element in XML Document
Sep 20, 2023
CVSS 9.8
EPSS 0.04
CVE-2019-25101 MEDIUM
OnShift TurboGears 1.0.11.10 - HTTP Response Splitting
Feb 04, 2023
CVSS 6.3
EPSS 0.01
CVE-2019-25095 LOW
ldapcherry < 1.0.0 - Cross-Site Scripting via URL Handler
Jan 05, 2023
CVSS 3.5
EPSS 0.01
CVE-2019-25091 LOW
nsupdate.info < 2019-05-19 - Sensitive Cookie Without 'HttpOnly' Flag in CSRF Cookie Handler
Dec 27, 2022
CVSS 3.7
EPSS 0.01
CVE-2019-10800 MEDIUM
codecov-python < 2.0.16 - OS Command Injection via Gcov Arguments
Jul 13, 2022
CVSS 6.5
EPSS 0.01
CVE-2019-20916 HIGH
pip < 19.2 - Directory Traversal via Content-Disposition Header
Sep 04, 2020
CVSS 7.5
EPSS 0.03
CVE-2019-14904 HIGH
Ansible < 2.7.15 - OS Command Injection via Solaris Zone Name Parameter
Aug 26, 2020
CVSS 7.3
EPSS 0.00
CVE-2019-14905 MEDIUM
Ansible Engine < 2.7.16 - OS Command Injection via nxos_file_copy Module
Mar 31, 2020
CVSS 5.6
EPSS 0.01
CVE-2019-15796 MEDIUM
python-apt <= 1.9.3ubuntu2 - Improper Authentication in Version Hash Validation
Mar 26, 2020
CVSS 4.7
EPSS 0.00
CVE-2019-15795 MEDIUM
python-apt <= 1.9.0ubuntu1 - Man-in-the-Middle via MD5 Checksum Validation
Mar 26, 2020
CVSS 4.7
EPSS 0.00
CVE-2019-10682 HIGH
django-nopassword < 5.0.0 - Cleartext Storage of Sensitive Information
Mar 18, 2020
CVSS 7.5
EPSS 0.01
CVE-2019-20477 CRITICAL
PyYAML 5.1-5.1.2 - Deserialization of Untrusted Data via Insufficient Class Restrictions
Feb 19, 2020
CVSS 9.8
EPSS 0.05
CVE-2019-16792 HIGH
Waitress < 1.4.0 - HTTP Request Smuggling via Double Content-Length Header
Jan 22, 2020
CVSS 7.1
EPSS 0.02
CVE-2019-16791 MEDIUM
Postfix-mta-sts-resolver <0.5.1 - Info Disclosure
Jan 22, 2020
CVSS 6.9
EPSS 0.01
CVE-2019-17361 CRITICAL
SaltStack Salt < 2019.2.0 - Unauthenticated Remote Code Execution via salt-api NET API
Jan 17, 2020
CVSS 9.8
EPSS 0.15
CVE-2019-16784 HIGH
PyInstaller <3.6 - Privilege Escalation
Jan 14, 2020
CVSS 7.0
EPSS 0.01
CVE-2019-12398 MEDIUM
Apache Airflow < 1.10.5 - Authenticated Stored Cross-Site Scripting via Metadata Database State Manipulation
Jan 14, 2020
CVSS 4.8
EPSS 0.02