Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2240932
AlmaLinux
5967
Alpaquita
16154
Alpine
4655
Android
3677
Azure Linux
17970
BellSoft Hardened Containers
769
Bitnami
9476
Chainguard
1048381
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68937
Echo
7865
GHC
3
GIT
109014
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148209
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25461
Red Hat
23525
Rocky Linux
4342
Root
19620
RubyGems
5327
SUSE
23442
SwiftURL
60
TuxCare
9918
Ubuntu
65983
VSCode
21
Wolfi
293786
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-14524
PyPI/bigquery-agent-analytics-tracing
Malicious code in bigquery-agent-analytics-tracing (PyPI)
26 Aug
No fix available
PYSEC-2026-3576
PyPI/hermes-agent
hermes-agent has an Uncontrolled Resource Consumption issue
04 Aug
No fix available
Severity - 5.5 (Medium)
PYSEC-2026-3575
PyPI/hermes-agent
hermes-agent has an Injection issue
04 Aug
Fix available
Severity - 2.1 (Low)
PYSEC-2026-3577
PyPI/hermes-agent
hermes-agent has an Injection issue
04 Aug
No fix available
Severity - 5.5 (Medium)
PYSEC-2026-3061
PyPI/serena-agent
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
13 Jul
Fix available
Severity - 8.3 (High)
PYSEC-2026-2510
PyPI/hermes-agent
Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
13 Jul
Fix available
Severity - 8.7 (High)
PYSEC-2026-2511
PyPI/hermes-agent
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
13 Jul
Fix available
Severity - 6.8 (Medium)
PYSEC-2026-2513
PyPI/hermes-agent
hermes-agent has an Injection issue
13 Jul
Fix available
Severity - 2.9 (Low)
PYSEC-2026-2512
PyPI/hermes-agent
hermes-agent has an Incorrect Comparison
13 Jul
Fix available
Severity - 1.9 (Low)
PYSEC-2026-2515
PyPI/hermes-agent
hermes-agent has a sandbox issue
13 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-2514
PyPI/hermes-agent
hermes-agent has an Injection issue
13 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-2509
PyPI/hermes-agent
hermes-agent has an Injection issue
13 Jul
Fix available
Severity - 5.5 (Medium)
PYSEC-2026-2526
PyPI/ironic-python-agent
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres
13 Jul
Fix available
Severity - 7.7 (High)
PYSEC-2026-2668
PyPI/ms-agent
MS-Agent vulnerable to Command Injection
13 Jul
No fix available
Severity - 6.5 (Medium)
MAL-2026-10195
PyPI/eth-agent
Malicious code in eth-agent (PyPI)
12 Jul
No fix available
GHSA-37h2-6p4f-mp3q
PyPI/serena-agent
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
08 Jul
Fix available
Severity - 8.3 (High)
Load more...
PyPI - OSV