pypi

5,093 tracked vulnerabilities.

CVE-2018-18548 MEDIUM
AjentiCP < 1.2.23.13 - Cross-Site Scripting via File Manager Filename
Oct 24, 2018
CVSS 6.1
EPSS 0.04
CVE-2018-16837 HIGH
Ansible 2.7.0a1-2.7.0 - Sensitive Information Exposure via ssh-keygen Parameter Leak
Oct 23, 2018
CVSS 7.8
EPSS 0.00
CVE-2018-18482 MEDIUM
libpg_query 10-1.0.2 - Denial of Service via Memory Leak in pg_query_raw_parse
Oct 18, 2018
CVSS 6.5
EPSS 0.01
CVE-2018-18074 HIGH
python/requests < 2.20.0 - Credential Exposure via HTTPS-to-HTTP Redirect
Oct 09, 2018
CVSS 7.5
EPSS 0.07
CVE-2018-1000809 HIGH
privacyIDEA < 2.23.2 - Denial of Service via Token Validation API
Oct 08, 2018
CVSS 7.5
EPSS 0.02
CVE-2018-1000808 MEDIUM
Python Cryptographic Authority pyopenssl <17.5.0 - Use After Free
Oct 08, 2018
CVSS 5.9
EPSS 0.02
CVE-2018-1000807 HIGH
Python Cryptographic Authority pyopenssl <17.5.0 - Use After Free
Oct 08, 2018
CVSS 8.1
EPSS 0.04
CVE-2018-1000805 HIGH
Paramiko 2.4.1 2.3.2 2.2.3 2.1.5 2.0.8 1.18.5 1.17.6 - Remote Code Execution via SSH Server Incorrect Access Control
Oct 08, 2018
CVSS 8.8
EPSS 0.04
CVE-2018-17983 CRITICAL
Mercurial < 4.7.2 - Out-of-bounds Read in Manifest Parser
Oct 04, 2018
CVSS 9.1
EPSS 0.02
CVE-2018-16984 MEDIUM
Django 2.1 - Unauthenticated Password Hash Exposure via Read-Only Password Widget
Oct 02, 2018
CVSS 4.9
EPSS 0.02
CVE-2018-16515 HIGH
Matrix Synapse < 0.33.3.1 - Improper Verification of Cryptographic Signature
Sep 18, 2018
CVSS 8.8
EPSS 0.02
CVE-2018-17175 MEDIUM
Marshmallow <2.15.1, 3.x <3.0.0b9 - Info Disclosure
Sep 18, 2018
CVSS 5.3
EPSS 0.02
CVE-2018-14636 MEDIUM
OpenStack Neutron < 11.0.4, 12.0.3, 13.0.0.0b2 - Unauthorized Traffic Inspection via Open vSwitch Integration Bridge
Sep 10, 2018
CVSS 5.3
EPSS 0.01
CVE-2018-14635 MEDIUM
OpenStack Neutron <13.0.0.0b2, <12.0.3, <11.0.5 - DoS
Sep 10, 2018
CVSS 6.5
EPSS 0.03
CVE-2018-16552 HIGH
MicroPyramid Django-CRM 0.2 - Cross-Site Request Forgery in User and Account Management
Sep 05, 2018
CVSS 8.8
EPSS 0.01
CVE-2018-16516 MEDIUM
Flask-Admin < 1.5.3 - Reflected Cross-Site Scripting via Crafted URL
Sep 05, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-16407 MEDIUM
Mayan EDMS < 3.0.3 - Cross-Site Scripting via Tag Label Handling
Sep 03, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-16406 MEDIUM
Mayan EDMS < 3.0.2 - Stored Cross-Site Scripting via Cabinet Label
Sep 03, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-16405 MEDIUM
Mayan EDMS < 3.0.2 - Cross-Site Scripting via Appearance App
Sep 03, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-14572 HIGH
conference-scheduler-cli < 0.10.1 - Remote Code Execution via Pickle Deserialization
Aug 28, 2018
CVSS 7.8
EPSS 0.02
CVE-2018-1000226 CRITICAL NUCLEI
Cobbler <2.6.11 - Privilege Escalation
Aug 20, 2018
CVSS 9.8
EPSS 0.12
CVE-2018-1000225 MEDIUM
Cobbler 2.0.0+ - Unauthenticated Stored Cross-Site Scripting via XMLRPC API
Aug 20, 2018
CVSS 6.1
EPSS 0.01
CVE-2018-1000656 HIGH
Pallets Project flask <0.12.3 - Info Disclosure
Aug 20, 2018
CVSS 7.5
EPSS 0.04
CVE-2018-15560 HIGH
PyCryptodome < 3.6.6 - Integer Overflow in AESNI Encryption/Decryption
Aug 20, 2018
CVSS 7.5
EPSS 0.02
CVE-2018-10917 MEDIUM
pulp < 2.16.0 - Path Traversal and Arbitrary File Write
Aug 15, 2018
CVSS 6.8
EPSS 0.01