Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2220837
AlmaLinux
5885
Alpaquita
15521
Alpine
4589
Android
2912
Azure Linux
17131
BellSoft Hardened Containers
744
Bitnami
9228
Chainguard
1019853
CleanStart
3432
CRAN
14
crates.io
2710
Debian
67347
Docker Hardened Images
1
Echo
2744
GHC
3
GIT
104447
GitHub Actions
55
Go
9149
Hackage
32
Hex
351
Julia
1713
Linux
28753
Mageia
6200
Maven
6998
MinimOS
142654
npm
228436
NuGet
1860
opam
29
openEuler
8674
openSUSE
14336
OSS-Fuzz
4003
Packagist
7042
Pub
11
PyPI
25073
Red Hat
23028
Rocky Linux
4229
Root
19464
RubyGems
4709
SUSE
23038
SwiftURL
59
TuxCare
9360
Ubuntu
64335
VSCode
21
Wolfi
330664
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16298
PyPI/urc
Malicious code in urc (PyPI)
yesterday
No fix available
MAL-2026-16296
PyPI/py-venv-doctor
Malicious code in py-venv-doctor (PyPI)
yesterday
No fix available
GHSA-xcw4-53cc-hv32
PyPI/mnemosyne-memory
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
2 days ago
Fix available
Severity - 9.1 (Critical)
GHSA-3w57-8xmc-8v26
PyPI/anyio
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
2 days ago
Fix available
Severity - 7.0 (High)
GHSA-82r6-8w77-94w6
PyPI/anyio
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
2 days ago
Fix available
Severity - 9.3 (Critical)
GHSA-5p39-cfhj-2xmp
PyPI/anyio
AnyIO process-pool workers can block indefinitely on undrained stderr
2 days ago
Fix available
Severity - 6.8 (Medium)
GHSA-39wr-7q6h-cf68
PyPI/lmdeploy
LMDeploy has an SSRF bypass
2 days ago
Fix available
Severity - 7.5 (High)
GHSA-3hmm-rh5q-gwwr
PyPI/lmdeploy
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
2 days ago
Fix available
Severity - 8.8 (High)
GHSA-2vh9-42vm-xmv2
PyPI/lmdeploy
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
2 days ago
Fix available
Severity - 9.8 (Critical)
MAL-2026-16274
PyPI/requests-auroras
Malicious code in requests-auroras (PyPI)
2 days ago
No fix available
MAL-2026-16275
PyPI/requests-triwes
Malicious code in requests-triwes (PyPI)
2 days ago
No fix available
MAL-2026-16269
PyPI/requests-asetwe
Malicious code in requests-asetwe (PyPI)
2 days ago
No fix available
MAL-2026-16268
PyPI/index-forum
Malicious code in index-forum (PyPI)
2 days ago
No fix available
MAL-2026-16267
PyPI/pyjstat-smooth
Malicious code in pyjstat-smooth (PyPI)
2 days ago
No fix available
GHSA-gjv8-xp57-g29c
PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the `IDENTIFIER` / `VALUE` selector sub-patterns
3 days ago
Fix available
Severity - 5.3 (Medium)
GHSA-j934-xhv5-fg8f
PyPI/soupsieve
Soup Sieve: Polynomial-time ReDoS (O(n²)) in the whitespace/comment trimming regex `RE_WS_END` (triggers on VALID selectors)
3 days ago
Fix available
Severity - 5.3 (Medium)
Load more...
PyPI - OSV