Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2309013
AlmaLinux
6003
Alpaquita
16176
Alpine
4655
Android
2912
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9517
Chainguard
1048512
CleanStart
5432
CRAN
14
crates.io
2768
Debian
68982
Docker Hardened Images
1
Echo
4008
GHC
3
GIT
107838
GitHub Actions
55
Go
9334
Hackage
33
Hex
365
Julia
1713
Linux
29270
Mageia
6237
Maven
7055
MinimOS
148534
npm
229266
NuGet
1869
opam
29
openEuler
8900
openSUSE
14651
OSS-Fuzz
4003
Packagist
7109
Pub
11
PyPI
25490
Red Hat
23535
Rocky Linux
4344
Root
19644
RubyGems
5369
SUSE
23454
SwiftURL
61
TuxCare
9676
Ubuntu
66099
VSCode
21
Wolfi
337011
WordPress
30313
ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-q43m-vhcp-mhvm
PyPI/docling
PyPI/docling-slim
Docling: `enable_local_fetch` is not enforced in HTML browser-rendering mode
4 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-ph3r-5jfg-f84f
PyPI/vllm
vLLM: Mirrored multimodal IPC caches desync after a rejected request — a later...
4 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-935w-9g4m-p28p
PyPI/vllm
vLLM: Harmony tool continuations drop `cache_salt` — restoring a cross-tenant...
4 hours ago
Fix available
Severity - 3.1 (Low)
GHSA-g6x2-hccm-hh4m
PyPI/werkzeug
Werkzeug safe_join() allows Windows special device names
4 hours ago
Fix available
Severity - 6.3 (Medium)
GHSA-v4x9-3549-crwv
PyPI/pymongo
PyMongo: PYTHON-5996 Heap out-of-bounds write via signed size overflow in BSON...
4 hours ago
Fix available
Severity - 7.5 (High)
GHSA-vp6j-j7w5-5xjj
PyPI/pymongo
PyMongo: PYTHON-5986 Host injection in PyMongo connection string parsing via...
4 hours ago
Fix available
Severity - 8.3 (High)
GHSA-qx36-8mw2-4r3x
PyPI/pymongo
PyMongo: PYTHON-5990 Forced Unix domain socket connection via a .sock KMS...
4 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-x33g-cr3x-6449
PyPI/pyjwt
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity...
4 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-x6mc-67gf-chw4
PyPI/vllm
vLLM: Qwen2-VL / Qwen3-VL video samplers bound on request-controlled...
4 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-58v5-2m8f-94pr
PyPI/vllm
vLLM: GLMGA video sampling permits request-driven CPU and memory exhaustion
4 hours ago
Fix available
Severity - 5.3 (Medium)
GHSA-ph72-cqr5-qpp7
PyPI/vllm
vLLM: Scale-out disaggregated multimodal transport trusts caller-supplied...
4 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-85xf-c7hm-whqw
PyPI/vllm
vLLM: Structured-output request errors escape the request boundary and...
4 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-2phq-3phc-84px
PyPI/vllm
vLLM: Flash late-interaction scoring caches query embeddings under a...
4 hours ago
Fix available
Severity - 4.2 (Medium)
GHSA-2823-qmq8-rwvj
PyPI/vllm
vLLM: Loose `cache_salt` validation lets a single request kill EngineCore on...
4 hours ago
Fix available
Severity - 6.5 (Medium)
GHSA-2cv4-cqwr-gwf7
PyPI/uv
crates.io/uv
uv: Path traversal on Windows through wheel extraction
4 hours ago
Fix available
Severity - 5.9 (Medium)
GHSA-5639-2j2p-m4mx
PyPI/mako
Mako: Path traversal via drive-letter URI on Windows in TemplateLookup
4 hours ago
Fix available
Severity - 6.5 (Medium)
Load more...
PyPI - OSV