pypi

5,093 tracked vulnerabilities.

CVE-2019-19911 HIGH
Pillow < 6.2.2 - Denial of Service via FpxImagePlugin Integer Overflow
Jan 05, 2020
CVSS 7.5
EPSS 0.02
CVE-2019-5064 HIGH
OpenCV < 4.2.0 - Heap Buffer Overflow via Crafted JSON File
Jan 03, 2020
CVSS 8.8
EPSS 0.11
CVE-2019-5063 HIGH
OpenCV 4.1.0 - Heap Buffer Overflow via Crafted XML File
Jan 03, 2020
CVSS 8.8
EPSS 0.21
CVE-2019-14864 MEDIUM
Ansible 2.7.0-2.7.14, 2.8.0-2.8.6, 2.9.0 - Sensitive Information Disclosure via Log File
Jan 02, 2020
CVSS 6.5
EPSS 0.02
CVE-2019-14859 CRITICAL
python-ecdsa < 0.13.3 - Improper Verification of Cryptographic Signature
Jan 02, 2020
CVSS 9.1
EPSS 0.02
CVE-2019-16789 HIGH
Waitress <1.4.0 - HTTP Request Smuggling
Dec 26, 2019
CVSS 7.1
EPSS 0.03
CVE-2019-16786 HIGH
Waitress < 1.4.0 - HTTP Request Smuggling via Transfer-Encoding Header Mishandling
Dec 20, 2019
CVSS 7.1
EPSS 0.03
CVE-2019-16785 HIGH
Waitress < 1.4.0 - HTTP Request Smuggling via Inconsistent CRLF Parsing
Dec 20, 2019
CVSS 7.1
EPSS 0.03
CVE-2019-19844 CRITICAL
Django < 1.11.27, 2.x < 2.2.9, 3.x < 3.0.1 - Account Takeover via Unicode Case Transformation Bypass
Dec 18, 2019
CVSS 9.8
EPSS 0.35
CVE-2019-12414 MEDIUM
Apache Superset < 0.32 - Unauthorized Database Name Exposure in SQLLab Dropdown
Dec 16, 2019
CVSS 5.3
EPSS 0.03
CVE-2019-12413 MEDIUM
Apache Incubator Superset <0.31 - Info Disclosure
Dec 16, 2019
CVSS 5.3
EPSS 0.03
CVE-2019-16778 LOW
TensorFlow < 1.15.0 - Heap Buffer Overflow in UnsortedSegmentSum
Dec 16, 2019
CVSS 2.6
EPSS 0.01
CVE-2019-19702 HIGH
modoboa-dmarc < 1.2.0 - XML External Entity Injection via DMARC Report Processing
Dec 10, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-19687 HIGH
OpenStack Keystone 15.0.0-16.0.0 - Info Disclosure
Dec 09, 2019
CVSS 8.8
EPSS 0.02
CVE-2019-19624 MEDIUM
OpenCV < 4.1.1 - Out-of-bounds Read in dis_flow.cpp
Dec 06, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-19588 HIGH
Validators <0.12.6 - Info Disclosure
Dec 05, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-19118 MEDIUM
Django 2.1 <2.1.15 & 2.2 <2.2.8 - Privilege Escalation
Dec 02, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-16766 HIGH
wagtail-2fa < 1.3.0 - Authentication Bypass via URL Manipulation
Nov 29, 2019
CVSS 8.7
EPSS 0.01
CVE-2019-14867 HIGH
FreeIPA 4.6.0-4.6.6, 4.7.0-4.7.3, 4.8.0-4.8.2 - Unauthenticated Denial of Service via Kerberos Key Parsing
Nov 27, 2019
CVSS 8.8
EPSS 0.06
CVE-2019-10195 MEDIUM
IPA <4.6.7, <4.7.4, <4.8.3 - Info Disclosure
Nov 27, 2019
CVSS 6.5
EPSS 0.01
CVE-2019-19275 HIGH
typed_ast 1.3.0-1.3.1 - Out-of-bounds Read in ast_for_arguments
Nov 26, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-19274 HIGH
typed_ast <1.3.2 - Memory Corruption
Nov 26, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-14856 MEDIUM
Ansible < 2.6.20, 2.7.14, 2.8.6 - Improper Authentication
Nov 26, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-14853 HIGH
python-ecdsa < 0.13.3 - Denial of Service via Malformed DER Signature Handling
Nov 26, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-10217 MEDIUM
Ansible 2.8.0-2.8.4 - Info Disclosure
Nov 25, 2019
CVSS 6.5
EPSS 0.02