pypi

5,097 tracked vulnerabilities.

CVE-2016-8628 HIGH
Ansible < 2.2.0 - Remote Code Execution via Fact Variable Injection
Jul 31, 2018
CVSS 7.6
EPSS 0.03
CVE-2016-8647 MEDIUM
Ansible < 2.2.1.0 - Improper Input Validation in mysql_user Module
Jul 26, 2018
CVSS 4.9
EPSS 0.01
CVE-2016-9587 HIGH
Ansible < 2.1.4 and < 2.2.1 - Remote Code Execution via Client Fact Data
Apr 24, 2018
CVSS 8.1
EPSS 0.18
CVE-2016-3954 MEDIUM
web2py < 2.14.2 - Unauthenticated Exposure of Sensitive Information via Status Endpoint
Feb 06, 2018
CVSS 5.5
EPSS 0.01
CVE-2016-3953 CRITICAL
web2py < 2.14.2 - Remote Code Execution via Hardcoded Encryption Key
Feb 06, 2018
CVSS 9.8
EPSS 0.03
CVE-2016-10516 MEDIUM
Werkzeug < 0.11.11 - Cross-Site Scripting via Exception Message Field
Oct 23, 2017
CVSS 6.1
EPSS 0.02
CVE-2016-8638 CRITICAL
ipsilon <2.0.2,1.2.1,1.1.2,1.0.3 - Info Disclosure
Jul 12, 2017
CVSS 9.1
EPSS 0.02
CVE-2016-3691 HIGH
Kallithea < 0.3.2 - Cross-Site Request Forgery via GET Request Method
Apr 24, 2017
CVSS 8.8
EPSS 0.01
CVE-2016-3076 MEDIUM
Pillow 2.5.0-3.1.1 - Heap-Based Buffer Overflow in j2k_encode_entry
Apr 24, 2017
CVSS 5.5
EPSS 0.03
CVE-2016-6519 MEDIUM
OpenStack Manila < 2.5.1 - Authenticated Stored Cross-Site Scripting via Metadata Field
Apr 21, 2017
CVSS 5.4
EPSS 0.01
CVE-2016-10321 CRITICAL
web2py < 2.14.6 - Unauthenticated Password Brute-Force via Improper Host Deny Check
Apr 10, 2017
CVSS 9.8
EPSS 0.03
CVE-2016-1517 MEDIUM
OpenCV 3.0.0 - Denial of Service via Corrupt Chunks
Apr 10, 2017
CVSS 5.5
EPSS 0.01
CVE-2016-1516 HIGH
OpenCV 3.0.0 - Double Free
Apr 10, 2017
CVSS 8.8
EPSS 0.02
CVE-2016-9243 HIGH
cryptography < 1.5.2 - Insufficient Key Length Validation in HKDF
Mar 27, 2017
CVSS 7.5
EPSS 0.03
CVE-2016-10149 HIGH
PySAML2 < 4.4.0 - XML External Entity Injection via SAML XML Request or Response
Mar 24, 2017
CVSS 7.5
EPSS 0.04
CVE-2016-7140 MEDIUM
Plone 3.3.x-3.3.6 4.x-4.3.11 5.x-5.0.6 - Cross-Site Scripting
Mar 07, 2017
CVSS 6.1
EPSS 0.02
CVE-2016-7139 MEDIUM
Plone 3.3.6-5.0.6 - Cross-Site Scripting
Mar 07, 2017
CVSS 6.1
EPSS 0.02
CVE-2016-7138 MEDIUM
Plone 3.3.x-3.3.6 4.x-4.3.11 5.x-5.0.6 - Cross-Site Scripting via URL Checking Infrastructure
Mar 07, 2017
CVSS 6.1
EPSS 0.02
CVE-2016-7137 MEDIUM
Plone 3.3.x-3.3.6 4.x-4.3.11 5.x-5.0.6 - Open Redirect via Referer or Came_From Parameter
Mar 07, 2017
CVSS 6.1
EPSS 0.02
CVE-2016-7136 MEDIUM
Plone 4.x-4.3.11 5.x-5.0.6 - Cross-Site Scripting via GET Request
Mar 07, 2017
CVSS 6.1
EPSS 0.02
CVE-2016-7135 MEDIUM
Plone 4.2.x-4.3.11 5.x-5.0.6 - Directory Traversal via Theme Resource Editor
Mar 07, 2017
CVSS 4.9
EPSS 0.03
CVE-2016-10127 CRITICAL
PySAML2 < 4.5.0 - XML External Entity Injection via SAML XML Request or Response
Mar 03, 2017
CVSS 9.0
EPSS 0.02
CVE-2016-4043 MEDIUM
Plone 5.0rc1-5.1a1 - Authenticated Restricted Python Bypass via Chameleon Template Editing
Feb 24, 2017
CVSS 4.9
EPSS 0.01
CVE-2016-4042 MEDIUM
Plone 3.3-5.1a1 - Unauthorized Information Disclosure of Content IDs
Feb 24, 2017
CVSS 5.3
EPSS 0.01
CVE-2016-4041 HIGH
Plone 4.0-5.1a1 - Unauthenticated Privilege Escalation via WebDAV Requests
Feb 24, 2017
CVSS 7.3
EPSS 0.01