pypi

4,708 tracked vulnerabilities.

CVE-2025-3108 HIGH
Llamaindex < 0.12.41 - Remote Code Execution
Jul 06, 2025
CVSS 7.5
EPSS 0.02
CVE-2025-53366 HIGH
mcp < 1.9.4 - Denial of Service via Malformed Request Validation Error
Jul 04, 2025
EPSS 0.00
CVE-2025-53365 HIGH
MCP Python SDK <1.10.0 - Use After Free
Jul 04, 2025
EPSS 0.00
CVE-2025-48379 HIGH
Pillow 11.2.0-11.2.9 - Heap-based Buffer Overflow in DDS Image Writing
Jul 01, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-6855 MEDIUM
Langchain-Chatchat <0.3.1 - Path Traversal
Jun 29, 2025
CVSS 5.5
EPSS 0.01
CVE-2025-6854 MEDIUM
Langchain-Chatchat <0.3.1 - Path Traversal
Jun 29, 2025
CVSS 4.3
EPSS 0.01
CVE-2025-6853 MEDIUM
Langchain-Chatchat <0.3.1 - Path Traversal
Jun 29, 2025
CVSS 6.3
EPSS 0.01
CVE-2025-6773 MEDIUM
HKUDS LightRAG < 1.3.8 - Path Traversal via File Upload
Jun 27, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-53002 HIGH
LLaMA-Factory <= 0.9.3 - Remote Code Execution via Malicious Checkpoint Path Parameter
Jun 26, 2025
CVSS 8.3
EPSS 0.04
CVE-2025-50213 CRITICAL
Apache Airflow Providers Snowflake <6.4.0 - Special Element Injection
Jun 24, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-52558 HIGH
changedetection.io < 0.50.4 - Cross-Site Scripting via Filter Error Handling
Jun 23, 2025
EPSS 0.00
CVE-2025-2828 CRITICAL
langchain < 0.0.28 - Server-Side Request Forgery via RequestsToolkit
Jun 23, 2025
CVSS 10.0
EPSS 0.00
CVE-2025-6518 MEDIUM
PySpur-Dev <0.1.18 - Improper Neutralization
Jun 23, 2025
CVSS 6.3
EPSS 0.00
CVE-2025-52967 MEDIUM
MLflow < 3.1.0 - Server-Side Request Forgery via Gateway Path Validation Bypass
Jun 23, 2025
CVSS 5.8
EPSS 0.00
CVE-2025-52556 CRITICAL
rfc3161-client < 1.0.3 - Improper Verification of Cryptographic Signature
Jun 21, 2025
EPSS 0.00
CVE-2025-6279 MEDIUM
Upsonic < 0.55.6 - Remote Code Execution via cloudpickle.loads Deserialization
Jun 19, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-6278 MEDIUM
upsonic < 0.55.6 - Path Traversal via file.filename Argument
Jun 19, 2025
CVSS 5.5
EPSS 0.01
CVE-2025-50182 MEDIUM
urllib3 2.2.0-2.5.0 - Open Redirect via Pyodide Runtime
Jun 19, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-50181 MEDIUM
urllib3 < 2.5.0 - Open Redirect via PoolManager Retry Configuration
Jun 19, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-6050 MEDIUM
Mezzanine < 6.1.1 - Authenticated Stored Cross-Site Scripting via Blog Post Title in Admin Interface
Jun 17, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-6167 MEDIUM
python-a2a < 0.5.6 - Path Traversal in create_workflow Function
Jun 17, 2025
CVSS 5.5
EPSS 0.00
CVE-2025-49134 MEDIUM
Weblate < 5.12 - Unauthorized Exposure of User IP Address in Audit Log Notifications
Jun 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-47951 MEDIUM
Weblate < 5.12 - Excessive Authentication Attempts via Second Factor Endpoint
Jun 16, 2025
CVSS 4.9
EPSS 0.00
CVE-2025-4565 MEDIUM
protobuf-python < 4.25.8 - Denial of Service via Recursive Protocol Buffers Parsing
Jun 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-22242 MEDIUM
Salt 3006.x < 3006.12 and 3007.x < 3007.4 - Denial of Service via File Read Operation
Jun 13, 2025
CVSS 5.6
EPSS 0.00