Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2278064
AlmaLinux
6003
Alpaquita
16176
Alpine
4655
Android
2912
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9517
Chainguard
1048510
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68964
Docker Hardened Images
1
Echo
4008
GHC
3
GIT
107763
GitHub Actions
55
Go
9330
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6237
Maven
7050
MinimOS
148441
npm
229197
NuGet
1869
opam
29
openEuler
8900
openSUSE
14577
OSS-Fuzz
4003
Packagist
7107
Pub
11
PyPI
25459
Red Hat
23535
Rocky Linux
4343
Root
19643
RubyGems
5331
SUSE
23441
SwiftURL
60
TuxCare
9676
Ubuntu
66094
VSCode
21
Wolfi
337011
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17472
PyPI/anthropic-sdk
Malicious code in anthropic-sdk (PyPI)
20 hours ago
No fix available
MAL-2026-17471
PyPI/caoxiltts
Malicious code in caoxiltts (PyPI)
yesterday
No fix available
MAL-2026-17469
PyPI/infrabench
Malicious code in infrabench (PyPI)
yesterday
No fix available
MAL-2026-17470
PyPI/voxcpmruntime
Malicious code in voxcpmruntime (PyPI)
2 days ago
No fix available
MAL-2026-17468
PyPI/voxcpmintel
Malicious code in voxcpmintel (PyPI)
2 days ago
No fix available
MAL-2026-17465
PyPI/voxcpmeval
Malicious code in voxcpmeval (PyPI)
2 days ago
No fix available
MAL-2026-17466
PyPI/voxcpmkit
Malicious code in voxcpmkit (PyPI)
2 days ago
No fix available
MAL-2026-17467
PyPI/voxcpmui4
Malicious code in voxcpmui4 (PyPI)
2 days ago
No fix available
MAL-2026-17464
PyPI/voxcpmui3
Malicious code in voxcpmui3 (PyPI)
2 days ago
No fix available
MAL-2026-17462
PyPI/echogen
Malicious code in echogen (PyPI)
2 days ago
No fix available
MAL-2026-17463
PyPI/voxcpmtts3
Malicious code in voxcpmtts3 (PyPI)
2 days ago
No fix available
MAL-2026-17461
PyPI/voxel-tts
Malicious code in voxel-tts (PyPI)
2 days ago
No fix available
GHSA-h46j-26q3-rggf
PyPI/headroom-ai
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH)
2 days ago
Fix available
Severity - 8.8 (High)
GHSA-v2f8-6655-7grj
PyPI/vibe-trading-ai
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
2 days ago
Fix available
Severity - 10.0 (Critical)
GHSA-5rmq-chc7-m22f
PyPI/vibe-trading-ai
Vibe-Trading file-read tools expose arbitrary server-readable files
2 days ago
Fix available
Severity - 7.5 (High)
GHSA-jqmf-mx4f-hfr6
PyPI/vibe-trading-ai
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
2 days ago
Fix available
Severity - 10.0 (Critical)
Load more...
PyPI - OSV