Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-921
  • PyPI/simplejson
simplejson before 2.6.1 vulnerable to array index error 06 Jul
  • Fix available
  • Severity - 5.9 (Medium)
MAL-2026-1908
  • PyPI/prometheus-analysis-1
Malicious code in prometheus-analysis-1 (PyPI) 18 Mar
  • No fix available
PYSEC-2026-1
  • PyPI/dydx-v4-client
A single post-release of dydx-v4-client contained obfuscated multi-stage loader 28 Jan
  • No fix available
MAL-2026-1
  • PyPI/sfnt2woff-zopfli
Malicious code in sfnt2woff-zopfli (PyPI) 01 Jan
  • No fix available
MAL-2025-4266
  • PyPI/web3-request-1-8-54
Malicious code in web3-request-1-8-54 (PyPI) 22 May 2025
  • No fix available
GHSA-qcgg-j2x8-h9g8
  • PyPI/django
Django has a potential denial-of-service vulnerability in IPv6 validation 14 Jan 2025
  • Fix available
  • Severity - 5.8 (Medium)
PYSEC-2025-1
  • PyPI/django
See record for full details 14 Jan 2025
  • Fix available
MAL-2024-11722
  • PyPI/test-test-asd-1
Malicious code in test-test-asd-1 (PyPI) 26 Jul 2024
  • No fix available
MAL-2025-953
  • PyPI/private-test-1
Malicious code in private-test-1 (PyPI) 26 Jul 2024
  • No fix available
MAL-2024-5456
  • PyPI/paquete-1
Malicious code in paquete-1 (PyPI) 25 Jun 2024
  • No fix available
PYSEC-2024-1
  • PyPI/gratient
gratient 0.5 contains credential harvesting code 03 Jan 2024
  • No fix available
PYSEC-2023-1
  • PyPI/adyen
See record for full details 24 Jan 2023
  • Fix available
GHSA-5rrg-rr89-x9mv
  • PyPI/ansible
Ansible Exposes Sensitive Information 25 May 2022
  • Fix available
  • Severity - 8.7 (High)
GHSA-7q8x-38mc-p84f
  • PyPI/mako
Mako contains Cross-site Scripting vulnerability 17 May 2022
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-39vm-p9mr-4r27
  • PyPI/beaker
Beaker Sensitive Information Disclosure vulnerability 17 May 2022
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-rvq6-mrpv-m6rm
  • PyPI/django
Code Injection in Django 17 May 2022
  • Fix available
  • Severity - 9.3 (Critical)