Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2180711
AlmaLinux
5857
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17041
BellSoft Hardened Containers
744
Bitnami
9212
Chainguard
1017602
CleanStart
3422
CRAN
14
crates.io
2710
Debian
67321
Echo
6523
GHC
3
GIT
106258
GitHub Actions
55
Go
9147
Hackage
32
Hex
350
Julia
1713
Linux
29368
Mageia
6188
Maven
6998
MinimOS
142127
npm
228435
NuGet
1860
opam
29
openEuler
8541
openSUSE
14317
OSS-Fuzz
4002
Packagist
7036
Pub
11
PyPI
25073
Red Hat
23028
Rocky Linux
4229
Root
19463
RubyGems
4709
SUSE
23039
SwiftURL
59
TuxCare
9199
Ubuntu
64326
VSCode
21
Wolfi
286865
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16298
PyPI/urc
Malicious code in urc (PyPI)
6 hours ago
No fix available
MAL-2026-16296
PyPI/py-venv-doctor
Malicious code in py-venv-doctor (PyPI)
15 hours ago
No fix available
GHSA-xcw4-53cc-hv32
PyPI/mnemosyne-memory
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
19 hours ago
Fix available
Severity - 9.1 (Critical)
GHSA-3w57-8xmc-8v26
PyPI/anyio
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
19 hours ago
Fix available
Severity - 7.0 (High)
GHSA-82r6-8w77-94w6
PyPI/anyio
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
19 hours ago
Fix available
Severity - 9.3 (Critical)
GHSA-5p39-cfhj-2xmp
PyPI/anyio
AnyIO process-pool workers can block indefinitely on undrained stderr
19 hours ago
Fix available
Severity - 6.8 (Medium)
GHSA-39wr-7q6h-cf68
PyPI/lmdeploy
LMDeploy has an SSRF bypass
19 hours ago
Fix available
Severity - 7.5 (High)
GHSA-3hmm-rh5q-gwwr
PyPI/lmdeploy
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
19 hours ago
Fix available
Severity - 8.8 (High)
GHSA-2vh9-42vm-xmv2
PyPI/lmdeploy
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
19 hours ago
Fix available
Severity - 9.8 (Critical)
MAL-2026-16274
PyPI/requests-auroras
Malicious code in requests-auroras (PyPI)
yesterday
No fix available
MAL-2026-16275
PyPI/requests-triwes
Malicious code in requests-triwes (PyPI)
yesterday
No fix available
MAL-2026-16269
PyPI/requests-asetwe
Malicious code in requests-asetwe (PyPI)
yesterday
No fix available
MAL-2026-16268
PyPI/index-forum
Malicious code in index-forum (PyPI)
yesterday
No fix available
MAL-2026-16267
PyPI/pyjstat-smooth
Malicious code in pyjstat-smooth (PyPI)
yesterday
No fix available
GHSA-gjv8-xp57-g29c
PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
yesterday
Fix available
Severity - 5.3 (Medium)
GHSA-j934-xhv5-fg8f
PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
yesterday
Fix available
Severity - 5.3 (Medium)
Load more...
PyPI - OSV