Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
610380
AlmaLinux
4582
Alpaquita
8726
Alpine
4048
Android
3262
BellSoft Hardened Containers
417
Bitnami
6834
Chainguard
5528
CleanStart
713
CRAN
14
crates.io
2195
Debian
54034
Echo
3139
GHC
3
GIT
81456
GitHub Actions
49
Go
6479
Hackage
30
Hex
57
Julia
410
Linux
15361
Mageia
5863
Maven
6292
MinimOS
24235
npm
216965
NuGet
1624
opam
11
openEuler
6292
openSUSE
12394
OSS-Fuzz
3817
Packagist
5998
Pub
11
PyPI
18558
Red Hat
19103
Rocky Linux
2895
Root
11705
RubyGems
1924
SUSE
20136
SwiftURL
50
Ubuntu
51656
VSCode
18
Wolfi
3496
ID
Packages
Summary
Published
arrow_upward
Attributes
ECHO-7db2-03aa-5591
Echo/python-pip
PyPI/pip
See record for full details
03 Feb
Fix available
GHSA-6vgw-5pg2-w6jp
PyPI/pip
pip Path Traversal vulnerability
02 Feb
Fix available
Severity - 2.0 (Low)
ECHO-ffe1-1d3c-d9bc
Echo/python-pip
PyPI/pip
See record for full details
25 Sep 2025
Fix available
GHSA-4xh5-x5gv-qwph
PyPI/pip
pip's fallback tar extraction doesn't check symbolic links point to extraction directory
24 Sep 2025
Fix available
Severity - 5.9 (Medium)
MAL-2025-41700
PyPI/malicious-pip-package-for-demo
Malicious code in malicious-pip-package-for-demo (PyPI)
28 Aug 2025
No fix available
MAL-2024-11597
PyPI/frexco-pip-requests
Malicious code in frexco-pip-requests (PyPI)
09 Dec 2024
No fix available
MAL-2024-11575
PyPI/dftester-pip
Malicious code in dftester-pip (PyPI)
27 Nov 2024
No fix available
MAL-2024-10105
PyPI/popeye-pip-v3
Malicious code in popeye-pip-v3 (PyPI)
22 Jul 2024
No fix available
MAL-2024-5483
PyPI/pip-rce
Malicious code in pip-rce (PyPI)
25 Jun 2024
No fix available
MAL-2024-5484
PyPI/pip-remote-access-test
Malicious code in pip-remote-access-test (PyPI)
25 Jun 2024
No fix available
MAL-2024-5482
PyPI/pip-goodthing
Malicious code in pip-goodthing (PyPI)
25 Jun 2024
No fix available
MAL-2024-5343
PyPI/malicious-pip-package-for-democdf
Malicious code in malicious-pip-package-for-democdf (PyPI)
25 Jun 2024
No fix available
MAL-2024-5042
PyPI/dero-pip
Malicious code in dero-pip (PyPI)
25 Jun 2024
No fix available
GHSA-mq26-g339-26xf
PyPI/pip
Command Injection in pip when used with Mercurial
25 Oct 2023
Fix available
Severity - 6.8 (Medium)
PYSEC-2023-228
PyPI/pip
See record for full details
25 Oct 2023
Fix available
Severity - 3.3 (Low)
MAL-2023-1388
PyPI/print-pip
Malicious code in print-pip (PyPI)
20 May 2023
No fix available
Load more...
(1 page left)
PyPI - OSV