Pypi
Products
75- 5 CVEs
- 3 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- d8s-html2 CVEspypi
- d8s-pdfs2 CVEspypi
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- View all 75 products →
Recent CVEs
80| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-79724 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | ||
| CVE-2022-42040 | Cri | 0.64 | 9.8 | 0.05 | Oct 11, 2022 | The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0. | ||
| CVE-2022-41387 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0. | ||
| CVE-2022-41385 | Cri | 0.64 | 9.8 | 0.01 | Oct 11, 2022 | The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0. | ||
| CVE-2022-40812 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0. | ||
| CVE-2022-40432 | Cri | 0.64 | 9.8 | 0.02 | Sep 19, 2022 | The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0. | ||
| CVE-2022-40425 | Cri | 0.64 | 9.8 | 0.01 | Sep 19, 2022 | The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0. | ||
| CVE-2022-34981 | Cri | 0.64 | 9.8 | 0.02 | Jul 22, 2022 | The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-30885 | Cri | 0.64 | 9.8 | 0.02 | Jun 24, 2022 | The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2. | ||
| CVE-2022-30882 | Cri | 0.64 | 9.8 | 0.02 | Jun 8, 2022 | pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed. | ||
| CVE-2022-30877 | Cri | 0.64 | 9.8 | 0.02 | Jun 8, 2022 | The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. | ||
| CVE-2026-87911 | Cri | 0.62 | 9.6 | 0.02 | Sep 9, 2026 | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a… | ||
| CVE-2026-15143 | Cri | 0.60 | 9.3 | 0.00 | Jul 10, 2026 | A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary… | ||
| CVE-2026-12701 | Cri | 0.59 | 9.0 | 0.01 | Jul 20, 2026 | A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a… | ||
| CVE-2026-12205 | Cri | 0.59 | 9.1 | 0.00 | Jun 15, 2026 | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later… | ||
| CVE-2026-45832 | Hig | 0.57 | 8.8 | 0.01 | Jun 12, 2026 | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints. | ||
| CVE-2022-34501 | Cri | 0.57 | 9.8 | 0.01 | Jul 22, 2022 | The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2022-34500 | Cri | 0.57 | 9.8 | 0.02 | Jul 22, 2022 | The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | ||
| CVE-2026-79721 | Hig | 0.56 | — | 0.00 | Sep 8, 2026 | Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project. | ||
| CVE-2026-97662 | Hig | 0.53 | 8.2 | 0.00 | Oct 1, 2026 | An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference… |
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
- risk 0.64cvss 9.8epss 0.05
The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.01
The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.
- risk 0.64cvss 9.8epss 0.02
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
- risk 0.64cvss 9.8epss 0.02
The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.
- risk 0.64cvss 9.8epss 0.02
pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed.
- risk 0.64cvss 9.8epss 0.02
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.
- risk 0.62cvss 9.6epss 0.02
An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a…
- risk 0.60cvss 9.3epss 0.00
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary…
- risk 0.59cvss 9.0epss 0.01
A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a…
- risk 0.59cvss 9.1epss 0.00
Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later…
- risk 0.57cvss 8.8epss 0.01
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
- risk 0.57cvss 9.8epss 0.01
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
- risk 0.57cvss 9.8epss 0.02
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
- risk 0.56cvss —epss 0.00
Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.
- risk 0.53cvss 8.2epss 0.00
An argument injection issue in the diff scan operation in AWS security-agent-mcp-server before version 0.2.0 might allow context-dependent threat actors to create, overwrite, or truncate arbitrary files on the host outside the intended workspace directory via a crafted reference…