VYPR
Vendor

Pypi

Products
62
CVEs
67
Across products
42
Status
Private

Products

62
View all 62 products →

Recent CVEs

67
View all 67 CVEs →
  • CVE-2022-42040CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.05

    The d8s-algorithms package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-dicts package. The affected version is 0.1.0.

  • CVE-2022-41387CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-pdfs package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

  • CVE-2022-41385CriOct 11, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-html package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-urls package. The affected version is 0.1.0.

  • CVE-2022-40812CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.

  • CVE-2022-40432CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-strings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0.

  • CVE-2022-40425CriSep 19, 2022
    risk 0.64cvss 9.8epss 0.01

    The d8s-html for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0.

  • CVE-2022-34981CriJul 22, 2022
    risk 0.64cvss 9.8epss 0.02

    The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-30885CriJun 24, 2022
    risk 0.64cvss 9.8epss 0.02

    The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.

  • CVE-2022-30882CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    pyanxdns package in PyPI version 0.2 is vulnerable to code execution backdoor. The impact is: execute arbitrary code (remote). When installing the pyanxdns package of version 0.2, the request package will be installed.

  • CVE-2022-30877CriJun 8, 2022
    risk 0.64cvss 9.8epss 0.02

    The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.

  • CVE-2026-15143CriJul 10, 2026
    risk 0.60cvss 9.3epss 0.00

    A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary…

  • CVE-2026-12701CriJul 20, 2026
    risk 0.59cvss 9.0epss 0.01

    A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a…

  • CVE-2026-12205CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later…

  • CVE-2026-45832HigJun 12, 2026
    risk 0.57cvss 8.8epss 0.00

    All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

  • CVE-2022-34501CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

  • CVE-2022-34500CriJul 22, 2022
    risk 0.57cvss 9.8epss 0.01

    The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.

  • CVE-2025-71357HigJun 21, 2026
    risk 0.53cvss 8.1epss 0.00

    picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.

  • CVE-2026-12048CriJun 19, 2026
    risk 0.53cvss 9.3epss 0.00

    Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks…

  • CVE-2026-12252HigJul 4, 2026
    risk 0.51cvss 7.8epss 0.00

    In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution. These classes accept user-controllable…

  • CVE-2026-48813HigAug 11, 2026
    risk 0.50cvss epss 0.00

    Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file…