Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
659234
AlmaLinux
4796
Alpaquita
9605
Alpine
4135
Android
3262
Azure Linux
12016
BellSoft Hardened Containers
467
Bitnami
7870
Chainguard
6382
CleanStart
1110
CRAN
14
crates.io
2401
Debian
56227
Echo
4028
GHC
3
GIT
81567
GitHub Actions
52
Go
6940
Hackage
30
Hex
101
Julia
845
Linux
15361
Mageia
5922
Maven
6486
MinimOS
41422
npm
218721
NuGet
1703
opam
14
openEuler
6749
openSUSE
12801
OSS-Fuzz
3883
Packagist
6285
Pub
11
PyPI
19650
Red Hat
20123
Rocky Linux
3135
Root
14084
RubyGems
1963
SUSE
20561
SwiftURL
51
Ubuntu
54342
VSCode
18
Wolfi
4098
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-2540
PyPI/gd-auth
Malicious code in gd-auth (PyPI)
10 Apr
No fix available
MAL-2026-2541
PyPI/gd-auth-sso
Malicious code in gd-auth-sso (PyPI)
10 Apr
No fix available
MAL-2026-847
PyPI/requests-auth-toolkit
Malicious code in requests-auth-toolkit (PyPI)
10 Feb
No fix available
GHSA-wv4w-6qv2-qqfg
PyPI/social-auth-app-django
Python Social Auth - Django has unsafe account association
09 Oct 2025
Fix available
Severity - 6.3 (Medium)
MAL-2025-191730
PyPI/flask-auth-sys
Malicious code in flask-auth-sys (PyPI)
02 Apr 2025
No fix available
MAL-2025-191731
PyPI/flask-auth-system
Malicious code in flask-auth-system (PyPI)
02 Apr 2025
No fix available
PYSEC-2024-272
PyPI/galaxy-auth
See record for full details
20 Sep 2024
Fix available
Severity - 5.4 (Medium)
MAL-2025-6479
PyPI/cloudx-auth
Malicious code in cloudx-auth (PyPI)
26 Jul 2024
No fix available
MAL-2024-5293
PyPI/killskids-auth
Malicious code in killskids-auth (PyPI)
25 Jun 2024
No fix available
GHSA-2gr8-3wc7-xhj3
PyPI/social-auth-app-django
social-auth-app-django affected by Improper Handling of Case Sensitivity
24 Apr 2024
Fix available
Severity - 4.9 (Medium)
PYSEC-2020-39
PyPI/django-two-factor-auth
github.com/Bouke/django-two-factor-auth
See record for full details
10 Jul 2020
Fix available
GHSA-vhr6-pvjm-9qwf
PyPI/django-two-factor-auth
User passwords are stored in clear text in the Django session
10 Jul 2020
Fix available
Severity - 6.0 (Medium)
PYSEC-2020-37
PyPI/django-basic-auth-ip-whitelist
See record for full details
24 Jun 2020
Fix available
GHSA-m38j-pmg3-v5x5
PyPI/django-basic-auth-ip-whitelist
Timing attack on django-basic-auth-ip-whitelist
23 Jun 2020
Fix available
Severity - 6.3 (Medium)
PyPI - OSV