pypi

5,097 tracked vulnerabilities.

CVE-2013-2233 HIGH
Ansible < 1.2.1 - Man-in-the-Middle Attack via SSH Host Key Caching Failure
May 04, 2018
CVSS 7.4
EPSS 0.02
CVE-2013-7459 CRITICAL
Python Cryptography Toolkit - Buffer Overflow
Feb 15, 2017
CVSS 9.8
EPSS 0.10
CVE-2013-2100
Gentoo Portage < 2.1.12.2 - Man-in-the-Middle Attack via Unverified X.509 Certificates
Sep 29, 2014
EPSS 0.02
CVE-2013-7323
python-gnupg <0.3.5 - Command Injection
Jun 09, 2014
EPSS 0.03
CVE-2013-2014
OpenStack Keystone < 2013.1 - Denial of Service via Long Requests
Jun 02, 2014
EPSS 0.03
CVE-2013-4347
python-oauth2 < 1.9rc1 - Weak Nonce Generation via make_nonce, generate_nonce, and generate_verifier Functions
May 20, 2014
EPSS 0.02
CVE-2013-4346
python-oauth2 - Replay Attack via Unchecked Nonce in Server.verify_request
May 20, 2014
EPSS 0.02
CVE-2013-6444
PyWBEM < 0.7 - Man-in-the-Middle Attack via Unverified X.509 Certificate
May 05, 2014
EPSS 0.01
CVE-2013-6418
pywbem < 0.7 - Man-in-the-Middle Certificate Spoofing via Separate Connection
May 05, 2014
EPSS 0.02
CVE-2013-7061
Plone 3.3-4.3.2 - Authenticated Information Disclosure via Search API
May 02, 2014
EPSS 0.01
CVE-2013-7060
Plone 3.3-4.3.2 - Unauthenticated Installation Path Exposure via FactoryTool File Object
May 02, 2014
EPSS 0.01
CVE-2013-7110
Transifex <0.10 - Man-in-the-Middle
May 02, 2014
EPSS 0.01
CVE-2013-4198
Plone 2.1-4.1, 4.2.x-4.2.5, 4.3.x-4.3.1 - Authenticated Password Change Bypass via Forgotten Password Email
Mar 11, 2014
EPSS 0.01
CVE-2013-4199
Plone 2.1-4.1 4.2.x-4.2.5 4.3.x-4.3.1 - Authenticated Denial of Service via Large Zip Archive Expansion
Mar 11, 2014
EPSS 0.01
CVE-2013-4197
Plone 2.1-4.1, 4.2.x-4.2.5, 4.3.x-4.3.1 - Authenticated Arbitrary Portrait Modification
Mar 11, 2014
EPSS 0.01
CVE-2013-4195
Plone 2.1-4.1, 4.2-4.2.5, 4.3-4.3.1 - Open Redirect via marmoset_patch.py, publish.py, and principiaredirect.py
Mar 11, 2014
EPSS 0.01
CVE-2013-4196
Plone 2.1-4.1 4.2-4.2.5 4.3-4.3.1 - Information Disclosure via Object Manager
Mar 11, 2014
EPSS 0.01
CVE-2013-4193
Plone 2.1-4.1, 4.2.x-4.2.5, 4.3.x-4.3.1 - Unauthenticated Field Hiding via Crafted URL
Mar 11, 2014
EPSS 0.01
CVE-2013-4194
Plone 2.1-4.1 4.2.x-4.2.5 4.3.x-4.3.1 - Information Disclosure via WYSIWYG Component Error Message
Mar 11, 2014
EPSS 0.01
CVE-2013-4192
Plone 2.1-4.1, 4.2-4.2.5, 4.3-4.3.1 - Authenticated Email Spoofing
Mar 11, 2014
EPSS 0.01
CVE-2013-4191
Plone 2.1-4.1 4.2.x-4.2.5 4.3.x-4.3.1 - Unauthenticated Sensitive Information Exposure via Zip Archive Generation
Mar 11, 2014
EPSS 0.01
CVE-2013-4189
Plone <4.3.1 - Info Disclosure
Mar 11, 2014
EPSS 0.01
CVE-2013-4190
Plone 2.1-4.1, 4.2.x-4.2.5, 4.3.x-4.3.1 - Cross-Site Scripting
Mar 11, 2014
EPSS 0.02
CVE-2013-4188
Plone 2.1-4.1 4.2.x-4.2.5 4.3.x-4.3.1 - Authenticated Denial of Service via Resource Retrieval
Mar 11, 2014
EPSS 0.01
CVE-2013-6437
OpenStack Nova < 2013.2.2 and icehouse < icehouse-2 - Authenticated Denial of Service via Unique os_type Settings
Mar 06, 2014
EPSS 0.02