Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
Vulnerabilities
search
All ecosystems
582761
AlmaLinux
4309
Alpaquita
8063
Alpine
3955
Android
2912
BellSoft Hardened Containers
309
Bitnami
6399
Chainguard
4832
CRAN
12
crates.io
1941
Debian
52045
Echo
2794
GHC
3
GIT
76842
GitHub Actions
37
Go
5332
Hackage
26
Hex
44
Julia
332
Linux
23018
Mageia
5792
Maven
6131
MinimOS
9331
npm
214278
NuGet
1516
openEuler
5792
openSUSE
10311
OSS-Fuzz
3733
Packagist
5587
Pub
10
PyPI
17606
Red Hat
18140
Rocky Linux
2598
Root
16823
RubyGems
1843
SUSE
17108
SwiftURL
46
Ubuntu
49962
VSCode
15
Wolfi
2934
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-595
PyPI/morty-package
Malicious code in morty-package (PyPI)
8 hours ago
No fix available
MAL-2026-593
PyPI/pypi-package-explore
Malicious code in pypi-package-explore (PyPI)
9 hours ago
No fix available
MAL-2026-590
PyPI/pytorch-mutex
Malicious code in pytorch-mutex (PyPI)
11 hours ago
No fix available
GHSA-qh4c-xf7m-gxfc
PyPI/vllm
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
11 hours ago
Fix available
Severity - 7.1 (High)
MAL-2026-562
PyPI/tabullates
Malicious code in tabullates (PyPI)
20 hours ago
No fix available
GHSA-63cw-57p8-fm3p
PyPI/pytorch
PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
yesterday
Fix available
Severity - 8.8 (High)
MAL-2026-548
PyPI/tabletas
Malicious code in tabletas (PyPI)
yesterday
No fix available
GHSA-r2jv-fwfr-4j8c
PyPI/askbot
askbot inexhaustive permissions check allows any user to modify a different user's profile picture
yesterday
Fix available
Severity - 5.3 (Medium)
MAL-2026-547
PyPI/solhint-plugin-hyperlane
Malicious code in solhint-plugin-hyperlane (PyPI)
yesterday
No fix available
GHSA-2q4j-m29v-hq73
PyPI/pypdf
pypdf has possible Infinite Loop when processing outlines/bookmarks
2 days ago
Fix available
Severity - 5.1 (Medium)
GHSA-8hf7-h89p-3pqj
PyPI/mobsf
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
2 days ago
Fix available
Severity - 8.1 (High)
GHSA-gcgx-chcp-hxp9
PyPI/gakido
Gakido vulnerable to HTTP Header Injection (CRLF Injection)
2 days ago
Fix available
Severity - 5.3 (Medium)
GHSA-wp53-j4wj-2cfg
PyPI/python-multipart
Python-Multipart has Arbitrary File Write via Non-Default Configuration
2 days ago
Fix available
Severity - 8.6 (High)
GHSA-hm8f-75xx-w2vr
PyPI/sigstore
sigstore CSRF possibility in OIDC authentication during signing
2 days ago
Fix available
GHSA-6p6h-rqr6-62mv
PyPI/gi-docgen
GI-DocGen vulnerable to Reflected XSS via unescaped query strings
2 days ago
Fix available
Severity - 6.1 (Medium)
GHSA-6r62-w2q3-48hf
PyPI/bentoml
BentoML has a Path Traversal via Bentofile Configuration
2 days ago
Fix available
Severity - 7.4 (High)
Load more...
PyPI - OSV