pypi

4,708 tracked vulnerabilities.

CVE-2025-65106 HIGH
langchain-core 1.0.0-1.0.6 - Template Injection via Untrusted Template Strings
Nov 21, 2025
EPSS 0.00
CVE-2025-62609 HIGH
MLX < 0.29.4 - Denial of Service via Malicious GGUF File Loading
Nov 21, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62608 CRITICAL
MLX < 0.29.4 - Heap-based Buffer Overflow in NumPy File Parser
Nov 21, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-62426 MEDIUM
vLLM 0.5.5-0.11.1 - Denial of Service via Unvalidated chat_template_kwargs Parameter
Nov 21, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62372 MEDIUM
vLLM 0.5.5-0.11.1 - Denial of Service via Multimodal Embedding Input Shape Mismatch
Nov 21, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-62164 HIGH
vLLM 0.10.2-0.11.1 - Remote Code Execution via Malicious Prompt Embedding Tensors
Nov 21, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-65015 HIGH
joserfc 1.3.3-1.3.4 and 1.4.0-1.4.1 - Denial of Service via Large JWT Payload
Nov 18, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-60455 HIGH
Modular Max Serve <25.6 - Code Injection
Nov 18, 2025
CVSS 8.4
EPSS 0.00
CVE-2025-65073 HIGH
OpenStack Keystone < 26.0.1, 27.0.0, 28.0.0 - Incorrect Authorization via AWS Signature
Nov 17, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-12765 HIGH
pgAdmin <= 9.9 - Improper Certificate Validation in LDAP Authentication
Nov 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-12764 HIGH
pgAdmin <= 9.9 - LDAP Injection via Username Parameter
Nov 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-12763 MEDIUM
pgAdmin 4 < 9.10 - OS Command Injection via Backup and Restore File Path
Nov 13, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-12762 CRITICAL
pgAdmin 4 < 9.10 - Remote Code Execution via PLAIN-format Dump File Restore
Nov 13, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-64512 HIGH
pdfminer.six < 20251107 - Remote Code Execution via Malicious Pickle File Deserialization
Nov 10, 2025
CVSS 8.6
EPSS 0.00
CVE-2025-64509 HIGH
Bugsink < 2.0.6 - Denial of Service via Brotli Decompression
Nov 10, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64508 HIGH
Bugsink < 2.0.5 - Denial of Service via Brotli Decompression Bomb
Nov 10, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64183 HIGH
OpenEXR 3.2.0-3.2.4 3.3.0-3.3.5 3.4.0-3.4.2 - Use-After-Free in PyObject_StealAttrString
Nov 10, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-64182 HIGH
OpenEXR 3.2.0-3.2.4 3.3.0-3.3.5 3.4.0-3.4.2 - Heap Overflow via Legacy Python InputFile Wrapper
Nov 10, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-64181 HIGH
OpenEXR 3.3.0-3.3.5 3.4.0-3.4.2 - Use of Uninitialized Variable in generic_unpack
Nov 10, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-62780 LOW NUCLEI
changedetection.io < 0.50.34 - Stored Cross-Site Scripting via Watch Update API
Nov 10, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-12967 HIGH
AWS Wrappers for Amazon Aurora PostgreSQL - Privilege Escalation
Nov 10, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-64496 HIGH
Open WebUI < 0.6.35 - Remote Code Execution via Direct Connections SSE Event Injection
Nov 08, 2025
CVSS 7.3
EPSS 0.00
CVE-2025-64495 HIGH
Open WebUI < 0.6.35 - Stored Cross-Site Scripting via Rich Text Prompt Insertion
Nov 08, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-64481 LOW
Datasette < 0.65.2 and 1.0a0-1.0a19 - Open Redirect via Double Slash Path
Nov 07, 2025
EPSS 0.00
CVE-2025-64439 HIGH
langgraph-checkpoint < 3.0.0 - Remote Code Execution via JsonPlusSerializer Deserialization
Nov 07, 2025
EPSS 0.01