Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.3
CVE-2023-38898
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disp…
Python
Patch available
HIGH 7.5
CVE-2023-36632
The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded whil…
Python
after 3.11.4
MEDIUM 5.5
CVE-2023-33595
CPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.
Python
Patch available
MEDIUM 6.1
CVE-2023-32681
Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an …
Requests
2.31.0+
HIGH 7.5
CVE-2023-24329EPSS 20%
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with bl…
Python
3.7.17 / 3.8.17+
MEDIUM 5.9
CVE-2022-40897
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or cust…
Setuptools
65.5.1+
HIGH 7.5
CVE-2022-45198
Pillow before 9.2.0 performs Improper Handling of Highly Compressed GIF Data (Data Amplification).
Pillow
9.2.0+
HIGH 7.5
CVE-2022-45199
Pillow before 9.3.0 allows denial of service via SAMPLESPERPIXEL.
Pillow
9.3.0+
HIGH 7.5
CVE-2022-45061
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3…
Python
after 3.10.8
HIGH 7.8
CVE-2022-42919
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiproces…
Python
3.9.16 / 3.10.9+
HIGH 7.5
CVE-2020-10735EPSS 6%
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to …
Python
3.7.14 / 3.8.14+
MEDIUM 5.3
CVE-2021-4189
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client t…
Python
3.6.14 / 3.7.11+
HIGH 7.4
CVE-2021-28861
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI…
Python
3.7.14 / 3.8.14+
CRITICAL 9.8
CVE-2022-30595
libImaging/TgaRleDecode.c in Pillow 9.1.0 has a heap buffer overflow in the processing of invalid TGA image files.
Pillow
No fix yet
CRITICAL 9.8
CVE-2022-28470
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
Pypi
after 0.13
HIGH 7.6
CVE-2015-20107EPSS 7%
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may…
Python
3.10.8+
CRITICAL 9.1
CVE-2022-24303
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
Pillow
9.0.1+
HIGH 7.0
CVE-2022-26488
In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local …
Python
after 3.10.2
MEDIUM 6.5
CVE-2021-3733
There's a flaw in urllib's AbstractBasicAuthHandler class. An attacker who controls a malicious HTTP server that an HTTP client (such as web browser)…
Python
3.6.14 / 3.7.11+
HIGH 7.5
CVE-2021-3737EPSS 12%
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP …
Python
3.6.14 / 3.7.11+
HIGH 7.5
CVE-2022-0391EPSS 8%
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into componen…
Python
3.6.14 / 3.7.11+
CRITICAL 9.8
CVE-2022-22817
PIL.ImageMath.eval in Pillow before 9.0.0 allows evaluation of arbitrary expressions, such as ones that use the Python exec method. A lambda expressi…
Pillow
9.0.1+
MEDIUM 6.5
CVE-2022-22815
path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path.
Pillow
9.0.0+
MEDIUM 6.5
CVE-2022-22816
path_getbbox in path.c in Pillow before 9.0.0 has a buffer over-read during initialization of ImagePath.Path.
Pillow
9.0.0+
HIGH 7.5
CVE-2021-23437
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
Pillow
8.3.2+
CRITICAL 9.8
CVE-2021-34552
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert funct…
Pillow
after 8.2.0
HIGH 7.5
CVE-2021-33503
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority reg…
Urllib3
1.26.5+
CRITICAL 9.1
CVE-2021-25287
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
Pillow
8.2.0+
CRITICAL 9.1
CVE-2021-25288
An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
Pillow
8.2.0+
HIGH 7.5
CVE-2021-28676
An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leadi…
Pillow
8.2.0+