Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2275154
AlmaLinux
5995
Alpaquita
16148
Alpine
4635
Android
2912
Azure Linux
17767
BellSoft Hardened Containers
764
Bitnami
9492
Chainguard
1047166
CleanStart
5235
CRAN
14
crates.io
2761
Debian
68901
Docker Hardened Images
1
Echo
4008
GHC
3
GIT
107619
GitHub Actions
55
Go
9330
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6237
Maven
7050
MinimOS
147950
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14544
OSS-Fuzz
4003
Packagist
7107
Pub
11
PyPI
25445
Red Hat
23506
Rocky Linux
4339
Root
19620
RubyGems
5327
SUSE
23439
SwiftURL
60
TuxCare
9676
Ubuntu
65992
VSCode
21
Wolfi
336742
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-h46j-26q3-rggf
PyPI/headroom-ai
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
5 hours ago
Fix available
Severity - 8.8 (High)
GHSA-v2f8-6655-7grj
PyPI/vibe-trading-ai
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
6 hours ago
Fix available
Severity - 10.0 (Critical)
GHSA-5rmq-chc7-m22f
PyPI/vibe-trading-ai
Vibe-Trading file-read tools expose arbitrary server-readable files
6 hours ago
Fix available
Severity - 7.5 (High)
GHSA-jqmf-mx4f-hfr6
PyPI/vibe-trading-ai
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
6 hours ago
Fix available
Severity - 10.0 (Critical)
GHSA-mhvh-fq92-pfmr
PyPI/geopy
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
6 hours ago
Fix available
Severity - 4.0 (Medium)
MAL-2026-17457
PyPI/voxeval
Malicious code in voxeval (PyPI)
7 hours ago
No fix available
GHSA-8mcx-5rqc-vhmf
PyPI/dulwich
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths
9 hours ago
Fix available
Severity - 8.8 (High)
GHSA-35mr-4567-66vg
PyPI/dulwich
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
10 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-8w8g-wq8h-fq33
PyPI/dulwich
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
10 hours ago
Fix available
Severity - 8.6 (High)
GHSA-5fqc-mrg8-w798
PyPI/dulwich
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
10 hours ago
Fix available
Severity - 8.6 (High)
GHSA-cm62-gvxx-vmxx
PyPI/dulwich
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
10 hours ago
Fix available
Severity - 8.6 (High)
MAL-2026-17455
PyPI/dedh-devops-automation
Malicious code in dedh-devops-automation (PyPI)
14 hours ago
No fix available
MAL-2026-17422
PyPI/shortneer
Malicious code in shortneer (PyPI)
yesterday
No fix available
MAL-2026-17421
PyPI/spo365-graph
Malicious code in spo365-graph (PyPI)
yesterday
No fix available
PYSEC-2026-4059
PyPI/jupyterlite-core
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
yesterday
Fix available
Severity - 6.8 (Medium)
PYSEC-2026-4056
PyPI/jupyterlab
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json)
yesterday
Fix available
Severity - 6.8 (Medium)
Load more...
PyPI - OSV