Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-15693
  • PyPI/py-devoli-common
Malicious code in py-devoli-common (PyPI) 24 Aug
  • No fix available
MAL-2026-13386
  • PyPI/decapod-common
Malicious code in decapod-common (PyPI) 06 Aug
  • No fix available
MAL-2026-10757
  • PyPI/dde-common
Malicious code in dde-common (PyPI) 16 Jul
  • No fix available
PYSEC-2026-2440
  • PyPI/dbt-common
dbt-common's commonprefix() doesn't protect against path traversal 13 Jul
  • Fix available
  • Severity - 2.0 (Low)
PYSEC-2026-1145
  • PyPI/apache-airflow-providers-common-sql
Apache Airflow Common SQL Provider Vulnerable to SQL Injection 07 Jul
  • Fix available
  • Severity - 8.8 (High)
MAL-2026-6262
  • PyPI/inversiones-common
Malicious code in inversiones-common (PyPI) 22 Jun
  • No fix available
MAL-2026-5817
  • PyPI/merino-common
Malicious code in merino-common (PyPI) 15 Jun
  • No fix available
MAL-2026-2181
  • PyPI/sonic-platform-common
Malicious code in sonic-platform-common (PyPI) 25 Mar
  • No fix available
GHSA-w75w-9qv4-j5xj
  • PyPI/dbt-common
dbt-common's commonprefix() doesn't protect against path traversal 05 Mar
  • Fix available
  • Severity - 2.0 (Low)
GHSA-6p6v-m64v-jx8q
  • Maven/org.apache.spark:spark-network-common_2.12
  • Maven/org.apache.spark:spark-network-common_2.13
  • PyPI/pyspark
Apache Spark has Inadequate Encryption Strength 15 Oct 2025
  • Fix available
  • Severity - 2.9 (Low)
MAL-2025-6562
  • PyPI/pb-common
Malicious code in pb-common (PyPI) 31 Jul 2025
  • No fix available
MAL-2025-6481
  • PyPI/common-test
Malicious code in common-test (PyPI) 31 Jul 2025
  • No fix available
MAL-2025-6461
  • PyPI/bavard-ml-common
Malicious code in bavard-ml-common (PyPI) 31 Jul 2025
  • No fix available
GHSA-5r62-mjf5-xwhj
  • PyPI/apache-airflow-providers-common-sql
Apache Airflow Common SQL Provider Vulnerable to SQL Injection 07 Apr 2025
  • Fix available
  • Severity - 8.8 (High)
GHSA-4xqv-47rm-37mm
  • PyPI/openc3
  • RubyGems/openc3
  • npm/@openc3/tool-common
OpenC3 stores passwords in clear text (`GHSL-2024-129`) 02 Oct 2024
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-vfj8-5pj7-2f9g
  • PyPI/openc3
  • RubyGems/openc3
  • npm/@openc3/tool-common
OpenC3 Cross-site Scripting in Login functionality (`GHSL-2024-128`) 02 Oct 2024
  • Fix available
  • Severity - 5.1 (Medium)