pypi

4,718 tracked vulnerabilities.

CVE-2024-46946 CRITICAL
langchain-experimental 0.1.17-0.3.0 - Remote Code Execution via LLMSymbolicMathChain Sympy Sympify
Sep 19, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-45601 HIGH
Mesop >=0.9.0 <0.12.4 - Unauthorized File Access via Insufficient Input Validation
Sep 18, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-45858 HIGH
Guardrails AI Guardrails <0.5.10 - RCE
Sep 18, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-35515 CRITICAL
sqlitedict <= 2.1.0 - Remote Code Execution via Insecure Deserialization
Sep 18, 2024
CVSS 9.8
EPSS 0.01
CVE-2024-45606 HIGH
Sentry 23.4.0-24.9.0 - Authenticated Authorization Bypass via Alert Rule Mute
Sep 17, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-45605 MEDIUM
Sentry 23.9.0-24.9.0 - Authenticated Authorization Bypass via User Alert Notification Deletion
Sep 17, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-8948 HIGH
MicroPython 1.23.0 - Heap-based Buffer Overflow in mpz_as_bytes
Sep 17, 2024
CVSS 7.3
EPSS 0.00
CVE-2024-8947 MEDIUM
MicroPython 1.22.2 - Use-After-Free in objarray Component
Sep 17, 2024
CVSS 5.6
EPSS 0.00
CVE-2024-8946 HIGH
MicroPython 1.23.0 - Heap-based Buffer Overflow in VFS Unmount Handler
Sep 17, 2024
CVSS 7.3
EPSS 0.00
CVE-2024-8939 MEDIUM
vllm - Denial of Service via Improper Handling of best_of Parameter
Sep 17, 2024
CVSS 6.2
EPSS 0.00
CVE-2024-8768 HIGH
vllm < 0.5.5 - Denial of Service via Empty Prompt
Sep 17, 2024
CVSS 7.5
EPSS 0.00
CVE-2024-5998 HIGH
langchain < 0.2.9 and langchain-community < 0.2.4 - Remote Code Execution via FAISS Deserialization
Sep 17, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-8865 LOW
composio < 0.5.8 - Path Traversal via File Parameter in API Download
Sep 15, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-8864 MEDIUM
composio < 0.5.6 - Code Injection in Calculator Function
Sep 15, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-8863 LOW
aimstack aim < 3.24.0 - Stored Cross-Site Scripting in Text Explorer via dangerouslySetInnerHTML
Sep 14, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-8862 HIGH
h2oai h2o-3 3.46.0.4 - Unauthenticated Remote Code Execution via JDBC Connection Handler Deserialization
Sep 14, 2024
CVSS 7.3
EPSS 0.02
CVE-2024-8775 MEDIUM
ansible-core >=2.17.0b1 <2.17.6 - Sensitive Information Exposure in Log Files via Vault Variable Handling
Sep 14, 2024
CVSS 5.5
EPSS 0.00
CVE-2024-6587 HIGH NUCLEI
litellm 1.38.10 - Server-Side Request Forgery via api_base Parameter
Sep 13, 2024
CVSS 7.5
EPSS 0.89
CVE-2024-45857 HIGH
Cleanlab >= 2.4.0 - Remote Code Execution via Malicious datalab.pkl File
Sep 12, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-45856 CRITICAL
MindsDB - Stored Cross-Site Scripting in ML Engine Enumeration
Sep 12, 2024
CVSS 9.0
EPSS 0.00
CVE-2024-45855 HIGH
MindsDB >= 23.10.2.0 - Remote Code Execution via Malicious Inhouse Model Deserialization
Sep 12, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-45854 HIGH
MindsDB >= 23.10.3.0 - Remote Code Execution via Malicious Inhouse Model Deserialization
Sep 12, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-45853 HIGH
MindsDB >= 23.10.2.0 - Remote Code Execution via Malicious Inhouse Model Deserialization
Sep 12, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-45852 HIGH
MindsDB >= 23.3.2.0 - Remote Code Execution via Untrusted Model Deserialization
Sep 12, 2024
CVSS 8.8
EPSS 0.00
CVE-2024-45851 HIGH
MindsDB 23.10.5.0-24.7.4.1 - Remote Code Execution via SharePoint INSERT Query
Sep 12, 2024
CVSS 8.8
EPSS 0.01