Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
597863
AlmaLinux
4555
Alpaquita
8575
Alpine
4001
Android
3260
BellSoft Hardened Containers
387
Bitnami
6752
Chainguard
5288
CleanStart
428
CRAN
14
crates.io
2146
Debian
53465
Echo
3055
GHC
3
GIT
79667
GitHub Actions
46
Go
6273
Hackage
27
Hex
53
Julia
342
Linux
15364
Mageia
5839
Maven
6234
MinimOS
18212
npm
216439
NuGet
1619
opam
11
openEuler
6219
openSUSE
12218
OSS-Fuzz
3807
Packagist
5884
Pub
10
PyPI
18278
Red Hat
18953
Rocky Linux
2824
Root
10902
RubyGems
1904
SUSE
19908
SwiftURL
48
Ubuntu
51517
VSCode
18
Wolfi
3318
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-frv4-x25r-588m
PyPI/giskard-agents
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment
7 hours ago
Fix available
Severity - 7.7 (High)
GHSA-46j8-vpx8-6p72
PyPI/homeassistant
Home Assistant has stored XSS in history-graphs
8 hours ago
Fix available
Severity - 1.1 (Low)
GHSA-r584-6283-p7xc
PyPI/homeassistant
Home Assistant has stored XSS in Map-card through malicious device name
8 hours ago
Fix available
Severity - 1.1 (Low)
GHSA-m959-cc7f-wv43
PyPI/cryptography
cryptography has incomplete DNS name constraint enforcement on peer names
9 hours ago
Fix available
Severity - 1.7 (Low)
GHSA-qh6h-p6c9-ff54
PyPI/langchain-core
LangChain Core has Path Traversal vulnerabilites in legacy
`
load_prompt
`
functions
9 hours ago
Fix available
Severity - 7.5 (High)
GHSA-8c4j-f57c-35cf
PyPI/langflow
PyPI/langflow-base
Langflow: Authenticated Users Can Read, Modify, and Delete Any Flow via Missing Ownership Check
9 hours ago
Fix available
Severity - 8.7 (High)
GHSA-58r7-4wr5-hfx8
PyPI/changedetection-io
Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters
10 hours ago
Fix available
Severity - 8.3 (High)
GHSA-vphc-468g-8rfp
PyPI/adx-mcp-server
Azure Data Explorer MCP Server: KQL Injection in multiple tools allows MCP client to execute arbitrary Kusto queries
10 hours ago
No fix available
Severity - 8.3 (High)
GHSA-m74m-f7cr-432x
PyPI/pyload-ng
pyLoad: Server-Side Request Forgery via Download Link Submission Enables Cloud Metadata Exfiltration
11 hours ago
No fix available
Severity - 9.3 (Critical)
PYSEC-2026-3
PyPI/telnyx
Two telnyx versions published containing credential harvesting malware
12 hours ago
No fix available
MAL-2026-2270
PyPI/copytrading
Malicious code in copytrading (PyPI)
12 hours ago
No fix available
MAL-2026-2273
PyPI/trustwallet
Malicious code in trustwallet (PyPI)
12 hours ago
No fix available
MAL-2026-2271
PyPI/metamask-api
Malicious code in metamask-api (PyPI)
12 hours ago
No fix available
MAL-2026-2269
PyPI/claude-lite
Malicious code in claude-lite (PyPI)
12 hours ago
No fix available
MAL-2026-2272
PyPI/solana-api
Malicious code in solana-api (PyPI)
12 hours ago
No fix available
MAL-2026-2268
PyPI/gemini-ai-api
Malicious code in gemini-ai-api (PyPI)
12 hours ago
No fix available
Load more...
PyPI - OSV