Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2221311
AlmaLinux
5889
Alpaquita
15521
Alpine
4589
Android
2912
Azure Linux
17153
BellSoft Hardened Containers
744
Bitnami
9238
Chainguard
1020038
CleanStart
3432
CRAN
14
crates.io
2717
Debian
67358
Docker Hardened Images
1
Echo
2744
GHC
3
GIT
104486
GitHub Actions
55
Go
9150
Hackage
32
Hex
351
Julia
1713
Linux
28753
Mageia
6203
Maven
6998
MinimOS
142702
npm
228503
NuGet
1860
opam
29
openEuler
8674
openSUSE
14336
OSS-Fuzz
4003
Packagist
7042
Pub
11
PyPI
25076
Red Hat
23056
Rocky Linux
4229
Root
19474
RubyGems
4709
SUSE
23045
SwiftURL
59
TuxCare
9385
Ubuntu
64335
VSCode
21
Wolfi
330668
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16366
PyPI/pullgetsage
Malicious code in pullgetsage (PyPI)
1 hour ago
No fix available
MAL-2026-16356
PyPI/starlette-healthchecks
Malicious code in starlette-healthchecks (PyPI)
4 hours ago
No fix available
MAL-2026-16346
PyPI/rrs
Malicious code in rrs (PyPI)
17 hours ago
No fix available
MAL-2026-16298
PyPI/urc
Malicious code in urc (PyPI)
2 days ago
No fix available
MAL-2026-16296
PyPI/py-venv-doctor
Malicious code in py-venv-doctor (PyPI)
2 days ago
No fix available
GHSA-xcw4-53cc-hv32
PyPI/mnemosyne-memory
Mnemosyne has JWT signature verification bypass sync server that allows authentication bypass
3 days ago
Fix available
Severity - 9.1 (Critical)
GHSA-3w57-8xmc-8v26
PyPI/anyio
AnyIO run_process/open_process ignores extra_groups and can retain parent supplementary groups
3 days ago
Fix available
Severity - 7.0 (High)
GHSA-82r6-8w77-94w6
PyPI/anyio
AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing
3 days ago
Fix available
Severity - 9.3 (Critical)
GHSA-5p39-cfhj-2xmp
PyPI/anyio
AnyIO process-pool workers can block indefinitely on undrained stderr
3 days ago
Fix available
Severity - 6.8 (Medium)
GHSA-39wr-7q6h-cf68
PyPI/lmdeploy
LMDeploy has an SSRF bypass
3 days ago
Fix available
Severity - 7.5 (High)
GHSA-3hmm-rh5q-gwwr
PyPI/lmdeploy
LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
3 days ago
Fix available
Severity - 8.8 (High)
GHSA-2vh9-42vm-xmv2
PyPI/lmdeploy
LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
3 days ago
Fix available
Severity - 9.8 (Critical)
MAL-2026-16274
PyPI/requests-auroras
Malicious code in requests-auroras (PyPI)
3 days ago
No fix available
MAL-2026-16275
PyPI/requests-triwes
Malicious code in requests-triwes (PyPI)
3 days ago
No fix available
MAL-2026-16269
PyPI/requests-asetwe
Malicious code in requests-asetwe (PyPI)
3 days ago
No fix available
MAL-2026-16268
PyPI/index-forum
Malicious code in index-forum (PyPI)
3 days ago
No fix available
Load more...
PyPI - OSV