Vulnerability index

Browse CVEs

208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Python MEDIUM 5.3
CVE-2023-38898

An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disp…

Patch available
Fix from $1,600 2023-08-15
Python HIGH 7.5
CVE-2023-36632

The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded whil…

Fix: after 3.11.4
Fix from $1,950 2023-06-25
Python MEDIUM 5.5
CVE-2023-33595

CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.

Patch available
Fix from $1,600 2023-06-07
Requests MEDIUM 6.1
CVE-2023-32681

Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an …

Fix: 2.31.0+
Fix from $1,600 2023-05-26
Python HIGH 7.5
CVE-2023-24329EPSS 20%

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with bl…

Fix: 3.7.17 / 3.8.17+
Fix from $1,950 2023-02-17
Setuptools MEDIUM 5.9
CVE-2022-40897

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or cust…

Fix: 65.5.1+
Fix from $1,600 2022-12-23
Pillow HIGH 7.5
CVE-2022-45198

Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).

Fix: 9.2.0+
Fix from $1,950 2022-11-14
Pillow HIGH 7.5
CVE-2022-45199

Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.

Fix: 9.3.0+
Fix from $1,950 2022-11-14
Python HIGH 7.5
CVE-2022-45061

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3…

Fix: after 3.10.8
Fix from $1,950 2022-11-09
Python HIGH 7.8
CVE-2022-42919

Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiproces…

Fix: 3.9.16 / 3.10.9+
Fix from $1,950 2022-11-07
Python HIGH 7.5
CVE-2020-10735EPSS 6%

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to …

Fix: 3.7.14 / 3.8.14+
Fix from $1,950 2022-09-09
Python MEDIUM 5.3
CVE-2021-4189

A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client t…

Fix: 3.6.14 / 3.7.11+
Fix from $1,600 2022-08-24
Python HIGH 7.4
CVE-2021-28861

Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI…

Fix: 3.7.14 / 3.8.14+
Fix from $1,950 2022-08-23
Pillow CRITICAL 9.8
CVE-2022-30595

libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.

No fix yet
Fix from $2,300 2022-05-25
Pypi CRITICAL 9.8
CVE-2022-28470

marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.

Fix: after 0.13
Fix from $2,300 2022-05-08
Python HIGH 7.6
CVE-2015-20107EPSS 7%

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may…

Fix: 3.10.8+
Fix from $1,950 2022-04-13
Pillow CRITICAL 9.1
CVE-2022-24303

Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

Fix: 9.0.1+
Fix from $2,300 2022-03-28
Python HIGH 7.0
CVE-2022-26488

In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local …

Fix: after 3.10.2
Fix from $1,950 2022-03-10
Python MEDIUM 6.5
CVE-2021-3733

There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser)…

Fix: 3.6.14 / 3.7.11+
Fix from $1,600 2022-03-10
Python HIGH 7.5
CVE-2021-3737EPSS 12%

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP …

Fix: 3.6.14 / 3.7.11+
Fix from $1,950 2022-03-04
Python HIGH 7.5
CVE-2022-0391EPSS 8%

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into componen…

Fix: 3.6.14 / 3.7.11+
Fix from $1,950 2022-02-09
Pillow CRITICAL 9.8
CVE-2022-22817

PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expressi…

Fix: 9.0.1+
Fix from $2,300 2022-01-10
Pillow MEDIUM 6.5
CVE-2022-22815

path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.

Fix: 9.0.0+
Fix from $1,600 2022-01-10
Pillow MEDIUM 6.5
CVE-2022-22816

path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.

Fix: 9.0.0+
Fix from $1,600 2022-01-10
Pillow HIGH 7.5
CVE-2021-23437

The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.

Fix: 8.3.2+
Fix from $1,950 2021-09-03
Pillow CRITICAL 9.8
CVE-2021-34552

Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert funct…

Fix: after 8.2.0
Fix from $2,300 2021-07-13
Urllib3 HIGH 7.5
CVE-2021-33503

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority reg…

Fix: 1.26.5+
Fix from $1,950 2021-06-29
Pillow CRITICAL 9.1
CVE-2021-25287

An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.

Fix: 8.2.0+
Fix from $2,300 2021-06-02
Pillow CRITICAL 9.1
CVE-2021-25288

An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.

Fix: 8.2.0+
Fix from $2,300 2021-06-02
Pillow HIGH 7.5
CVE-2021-28676

An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leadi…

Fix: 8.2.0+
Fix from $1,950 2021-06-02