Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
628459
AlmaLinux
4656
Alpaquita
8786
Alpine
4049
Android
3261
Azure Linux
12016
BellSoft Hardened Containers
428
Bitnami
6971
Chainguard
5697
CleanStart
757
CRAN
14
crates.io
2216
Debian
54289
Echo
3180
GHC
3
GIT
81474
GitHub Actions
49
Go
6562
Hackage
30
Hex
57
Julia
505
Linux
15361
Mageia
5876
Maven
6324
MinimOS
26712
npm
217427
NuGet
1657
opam
12
openEuler
6386
openSUSE
12477
OSS-Fuzz
3829
Packagist
6076
Pub
11
PyPI
18681
Red Hat
19342
Rocky Linux
2944
Root
11955
RubyGems
1933
SUSE
20399
SwiftURL
50
Ubuntu
52346
VSCode
18
Wolfi
3643
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mjw2-v2hm-wj34
PyPI/dagster
PyPI/dagster-deltalake
PyPI/dagster-duckdb
PyPI/dagster-gcp
PyPI/dagster-snowflake
... 1 more
Dagster Vulnerable to SQL Injection via Dynamic Partition Keys in Database I/O Manager Integrations
3 days ago
Fix available
Severity - 8.3 (High)
GHSA-339r-cjv9-x78g
PyPI/llama-index-retrievers-duckdb-retriever
LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
20 Mar 2025
Fix available
Severity - 9.8 (Critical)
GHSA-w2gf-jxc9-pf2q
PyPI/duckdb
sniff_csv provides filesystem access even when enable_external_access is disabled in duckdb
21 Jan 2025
Fix available
Severity - 7.5 (High)
PYSEC-2024-203
PyPI/duckdb
github.com/duckdb/duckdb
See record for full details
24 Jul 2024
Fix available
Severity - 7.5 (High)
PYSEC-2024-25
PyPI/duckdb
See record for full details
30 Jan 2024
Fix available
Severity - 9.8 (Critical)
PyPI - OSV