pypi

4,708 tracked vulnerabilities.

CVE-2025-57751 HIGH
pyload-ng < 0.5.0b3.dev92 - Denial of Service via Unverified jk Parameter
Aug 21, 2025
EPSS 0.00
CVE-2025-48956 HIGH
vLLM 0.1.0-0.10.1.0 - Unauthenticated Denial of Service via Large HTTP Header
Aug 21, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-54364 MEDIUM
Microsoft Knack 0.12.0 - Regular Expression Denial of Service in option_descriptions
Aug 20, 2025
EPSS 0.01
CVE-2025-54363 MEDIUM
Microsoft Knack 0.12.0 - Denial of Service via Inefficient Regular Expression in knack.introspection
Aug 20, 2025
EPSS 0.01
CVE-2025-55214 MEDIUM
Copier 7.1.0-9.9.0 - Path Traversal and Arbitrary File Write via Pathjoin Filter
Aug 18, 2025
EPSS 0.00
CVE-2025-55201 HIGH
Copier < 9.9.1 - Path Traversal via Unconstrained Pathlib Path Objects
Aug 18, 2025
EPSS 0.00
CVE-2025-50817 MEDIUM
Python-Future 1.0.0 - Code Injection
Aug 14, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-55675 MEDIUM
Apache Superset <5.0.0 - Info Disclosure
Aug 14, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-55674 MEDIUM
Apache Superset <5.0.0 - Info Disclosure
Aug 14, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-55673 MEDIUM
Apache Superset <4.1.3 - Info Disclosure
Aug 14, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-55672 MEDIUM
Apache Superset < 5.0.0 - Authenticated Stored Cross-Site Scripting in Chart Column Label
Aug 14, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-55197 HIGH
pypdf < 6.0.0 - Denial of Service via FlateDecode Filter RAM Exhaustion
Aug 13, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-54791 MEDIUM
OMERO.web < 5.29.2 - Information Disclosure via Forgot Password Error Message
Aug 13, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-55156 HIGH
pyLoad <0.5.0b3.dev91 - SQL Injection
Aug 11, 2025
EPSS 0.00
CVE-2025-8747 HIGH
Keras 3.0.0-3.10.0 - Remote Code Execution via Model.load_model Safe Mode Bypass
Aug 11, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-55149 MEDIUM
Tiny-Scientist <0.1.1 - Path Traversal
Aug 09, 2025
EPSS 0.00
CVE-2025-55013 MEDIUM
Assemblyline 4 <4.6.1.dev138 - Path Traversal
Aug 09, 2025
CVSS 4.2
EPSS 0.00
CVE-2025-54886 HIGH
skops < 0.13.0 - Remote Code Execution via Joblib Fallback in Card.get_model
Aug 08, 2025
CVSS 8.4
EPSS 0.00
CVE-2025-54952 CRITICAL
ExecuTorch <8f062d3f661e20bb19b24b767b9a9a46e8359f2b - Code Injection
Aug 08, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-54368 MEDIUM
Pypi UV < 0.8.6 - Interpretation Conflict
Aug 08, 2025
EPSS 0.00
CVE-2025-54951 CRITICAL
ExecuTorch < 0.7.0 - Heap-based Buffer Overflow in Model Loading
Aug 07, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-54950 CRITICAL
ExecuTorch < 0.7.0 - Out-of-bounds Read in Model Loading
Aug 07, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-54949 CRITICAL
ExecuTorch < 0.7.0 - Heap-based Buffer Overflow in Model Loading
Aug 07, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-30405 CRITICAL
ExecuTorch < 0.7.0 - Integer Overflow in Model Loading
Aug 07, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-30404 CRITICAL
ExecuTorch <d158236b1dc84539c1b16843bc74054c9dcba006 - Code Injection
Aug 07, 2025
CVSS 9.8
EPSS 0.00